Uploaded image for project: 'Mesos'
  1. Mesos
  2. MESOS-8909

Scrubbing value secret from HTTP responses

    XMLWordPrintableJSON

Details

    • Task
    • Status: Open
    • Major
    • Resolution: Unresolved
    • None
    • None
    • security

    Description

      Mesos supports a value based secret. However, I believe some HTTP endpoints and v1 operator responses could leak this information.

      The goal here is to make sure these endpoints do not leak the information.

      We did some quick research and gather the following list in this Google doc.

      Attachments

        Activity

          People

            Unassigned Unassigned
            zhitao Zhitao Li
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated: