Nixpkgs Security Tracker

Login with GitHub

Suggestion detail

Dismissed
updated 6 days, 21 hours ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    11 packages
    • monitoring-plugins
    • perlPackages.MonitoringPlugin
    • perl5Packages.MonitoringPlugin
    • haskellPackages.gogol-monitoring
    • perl538Packages.MonitoringPlugin
    • perl540Packages.MonitoringPlugin
    • python312Packages.google-cloud-monitoring
    • python313Packages.google-cloud-monitoring
    • python314Packages.google-cloud-monitoring
    • home-assistant-component-tests.victron_remote_monitoring
    • tests.home-assistant-component-tests.victron_remote_monitoring
  • @LeSuisse dismissed
Improper Access Control in github.com/ctfer-io/monitoring

The CTFer.io Monitoring component is in charge of the collection, process and storage of various signals (i.e. logs, metrics and distributed traces). Prior to 0.2.1, due to a mis-written NetworkPolicy, a malicious actor can pivot from a component to any other namespace. This breaks the security-by-default property expected as part of the deployment program, leading to a potential lateral movement. This vulnerability is fixed in 0.2.1.

Affected products

monitoring
  • ==< 0.2.1
Ignored packages (11)
Not present in nixpkgs