Uploaded image for project: 'Mesos'
  1. Mesos
  2. MESOS-8909

Scrubbing value secret from HTTP responses

Attach filesAttach ScreenshotAdd voteVotersWatch issueWatchersLinkCloneUpdate Comment AuthorReplace String in CommentUpdate Comment VisibilityDelete Comments
    XMLWordPrintableJSON

Details

    • Task
    • Status: Open
    • Major
    • Resolution: Unresolved
    • None
    • None
    • security

    Description

      Mesos supports a value based secret. However, I believe some HTTP endpoints and v1 operator responses could leak this information.

      The goal here is to make sure these endpoints do not leak the information.

      We did some quick research and gather the following list in this Google doc.

      Attachments

        Activity

          This comment will be Viewable by All Users Viewable by All Users
          Cancel

          People

            Unassigned Unassigned
            zhitao Zhitao Li

            Dates

              Created:
              Updated:

              Slack

                Issue deployment