Project

General

Profile

Actions

Bug #5907

closed

User story #6363: Secure agent/server communication

Any user can forge a fake report

Added by Benoît PECCATTE over 9 years ago. Updated 9 months ago.

Status:
Rejected
Priority:
N/A
Assignee:
-
Category:
Security
Severity:
Critical - prevents main use of Rudder | no workaround | data loss | security
UX impact:
User visibility:
First impressions of Rudder
Effort required:
Large
Priority:
0
Name check:
Fix check:
Regression:

Description

This is a vulnerability.
Any user can write to syslog.
Therefore, any user can create a fake report telling rudder there is a problem (or there is no problem).


Related issues 1 (0 open1 closed)

Related to Rudder - Architecture #14008: Replace syslog by an HTTPS based communication for reportingReleasedAlexis MoussetActions
Actions

Also available in: Atom PDF