Skip to content

Activities API is not namespace restricted #172

@demarna1

Description

@demarna1

Checks

Kubeflow Version

latest

Kubeflow Platform

Kubeflow Manifests

Kubernetes Distribution

EKS

Kubernetes Version

Client Version: v1.33.2
Server Version: v1.33.5-eks-3025e55

Description

InfoSec issue: Activities API is not namespace restricted.

Note how user does not have access to the serving-test-s3 namespace in the dropdown:

Image

Yet the user can hit the /api/activities/<namespace> directly and view events in another users namespace:

Image

Relevant Logs

Metadata

Metadata

Assignees

No one assigned

    Labels

    kind/bugkind - things not working properlypriority/needs-triagepriority - needs to be triaged

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions