-
Notifications
You must be signed in to change notification settings - Fork 30
Open
Labels
kind/bugkind - things not working properlykind - things not working properlypriority/needs-triagepriority - needs to be triagedpriority - needs to be triaged
Description
Checks
- I have searched the existing issues.
- My issue is related to one of the components in the
kubeflow/dashboardrepository.
Kubeflow Version
latest
Kubeflow Platform
Kubeflow Manifests
Kubernetes Distribution
EKS
Kubernetes Version
Client Version: v1.33.2
Server Version: v1.33.5-eks-3025e55Description
InfoSec issue: Activities API is not namespace restricted.
Note how user does not have access to the serving-test-s3 namespace in the dropdown:
Yet the user can hit the /api/activities/<namespace> directly and view events in another users namespace:
Relevant Logs
Metadata
Metadata
Assignees
Labels
kind/bugkind - things not working properlykind - things not working properlypriority/needs-triagepriority - needs to be triagedpriority - needs to be triaged