Security context

What an agent needs to avoid regressing past fixes and find the next vuln in this repo.

easzlab/kubeasz
master @ 4aafea3
3
Fixes
0
CVEs
HIGH
Peak severity
Highlights
Auth Bypass: 1 prior fix. Scrutinize any change in this area.
(roles/kube-node/templates/kube-proxy.service.j2): most-fixed (1 issue). Treat as high-risk during review.
1 high-severity fix in this history; regressions here are high-impact.
Recurring patterns

The bug types that recur here, drawn from past fixes, not open vulnerabilities.

Auth Bypass: Disabling anonymous authentication is critical for securing kubelet HTTPS endpoints on Kubernetes nodes to prevent unauthorized access to sensitive node APIs.
Use of Hard-coded Credentials: A hard-coded default read-only credential in basic authentication configurations allows unauthorized read-only API access unless replaced with dynamically generated passwords.
Bypassing Physical Security: Inappropriate configuration of cluster-cidr flags in kube-proxy causes unexpected SNAT on cross-node traffic, rendering Calico source-IP-based network policies ineffective.