| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
This document defines security reporting, handling, disclosure, and audit information for the Flux project and community.
Also see our Flux Security documentation landing page for an overview of project security information geared toward end users.
We're very thankful for – and if desired happy to credit – security researchers and users who report vulnerabilities to the Flux community.
Current Security Team members:
| Name | GitHub | Key URL | Fingerprint |
|---|---|---|---|
| Scott Rigby | @scottrigby | https://keybase.io/r6by/pgp_keys.asc | 208D D36E D5BB 3745 A167 43A4 C7C6 FBB5 B91C 1155 |
| Hidde Beydals | @hiddeco | https://keybase.io/hidde/pgp_keys.asc | C910 7A9B 55A4 DD77 062B 9731 B6E3 6A6A C54A CD59 |
Vulnerability disclosures are emailed to the Flux Dev mailing list https://lists.cncf.io/g/cncf-flux-dev and announced publicly. Disclosures will contain an overview, details about the vulnerability, a fix that will typically be an update, and optionally a workaround if one is available.
We will coordinate publishing disclosures and security releases in a way that is realistic and necessary for end users. We prefer to fully disclose the vulnerability as soon as possible once a user mitigation is available. Disclosures will always be published in a timely manner after a release is published that fixes the vulnerability.
Here is an overview of all our published security advisories.
| Date | CVE | Title | Severity | Affected version(s) | Reported by |
|---|---|---|---|---|---|
| 2021-11-10 | CVE-2021-41254 | Privilege escalation to cluster admin on multi-tenant Flux | High | < 0.18.0 | ADA Logics |
| Back | FazBrowse Home | New Git URL |