Skip to content

Fix initial release#17

Merged
ArangoGutierrez merged 1 commit intomainfrom
containerdversion
Feb 20, 2024
Merged

Fix initial release#17
ArangoGutierrez merged 1 commit intomainfrom
containerdversion

Conversation

@ArangoGutierrez
Copy link
Collaborator

No description provided.

Signed-off-by: Carlos Eduardo Arango Gutierrez <eduardoa@nvidia.com>
@ArangoGutierrez ArangoGutierrez self-assigned this Feb 20, 2024
@ArangoGutierrez ArangoGutierrez merged commit 7ffaf5e into main Feb 20, 2024
@ArangoGutierrez ArangoGutierrez deleted the containerdversion branch February 20, 2024 17:08
ArangoGutierrez added a commit to ArangoGutierrez/holodeck that referenced this pull request Feb 12, 2026
User-controlled label keys/values from YAML config were directly
interpolated into kubectl commands via fmt.Sprintf, enabling command
injection. Add label validation against Kubernetes label pattern.
Also validate PrivateIP with net.ParseIP before grep interpolation.

Audit findings NVIDIA#17 (MEDIUM), NVIDIA#18 (MEDIUM).

Signed-off-by: Carlos Eduardo Arango Gutierrez <eduardoa@nvidia.com>
ArangoGutierrez added a commit that referenced this pull request Feb 13, 2026
#656)

User-controlled label keys/values from YAML config were directly
interpolated into kubectl commands via fmt.Sprintf, enabling command
injection. Add label validation against Kubernetes label pattern.
Also validate PrivateIP with net.ParseIP before grep interpolation.

Audit findings #17 (MEDIUM), #18 (MEDIUM).

Signed-off-by: Carlos Eduardo Arango Gutierrez <eduardoa@nvidia.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant