Dapr june 2023 fuzzing audit reportFuzzCryptoKeysAny github.com/dapr/kit/crypto 9 FuzzCryptoKeysJson github.com/dapr/kit/crypto 10 FuzzCryptoKeysRaw github.com/dapr/kit/crypto 11 FuzzSymmetric github.com/dapr/kit/crypto 12 FuzzAescbcaead github github.com/dapr/kit/crypto/aescbcaead 13 FuzzParseEnvString github.com/dapr/dapr/pkg/injector/sidecar 14 FuzzIsOperationAllowedByAccessCo ntrolPolicy github.com/dapr/dapr/pkg/acl 15 FuzzIsEndpointAllowed FuzzCryptoKeysAny This fuzzer tests key parsing and serialization routines in github.com/dapr/kit/crypto. The fuzzer carries out three steps: It first creates a new key using the test case as the raw bytes0 码力 | 19 页 | 690.59 KB | 1 年前3
Dapr july 2020 security audit reportSentry-services and Operator-services. ▪ In further scope were a sample python-app (for testing), crypto implementations, secrets storage features, network filtering features, pub/sub mechanism implementations0 码力 | 19 页 | 267.84 KB | 1 年前3
Dapr september 2023 security audit reporthttps://github.com/dapr/components-contrib/pull/3090/files Some components allow the user to skip TLS verification which per default is disabled which is positive for Daprs security posture. Most modules e64ed724e4bd3e528a80/interna l/component/kafka/sasl_oauthbearer.go#L77 tlsConfig := &tls.Config{ MinVersion: tls.VersionTLS12, InsecureSkipVerify: ts.skipCaVerify, } The Kafka component also logs0 码力 | 47 页 | 1.05 MB | 1 年前3
共 3 条
- 1













