devtron icon indicating copy to clipboard operation
devtron copied to clipboard

Bug: Security vulnerabilities in devtron

Open 012git012 opened this issue 3 months ago • 4 comments

📜 Description

Hello @prakash100198 @vikramdevtron

Our team previously reached out to you regarding the vulnerabilities in devtron that we reported (https://github.com/devtron-labs/devtron/issues/6796).

Thank you again for remediating these vulnerabilities.

Please review our comments in the corresponding advisories. The researcher believes that one of these vulnerabilities may still be reproducible, so we kindly ask you to check it.

We would also appreciate it if you could share your planned timeline for disclosure. Additionally, we ask you to register CVEs and publish the advisories.

Thank you for your cooperation.

👟 Reproduction steps

👍 Expected behavior

👎 Actual Behavior

☸ Kubernetes version

Cloud provider

🌍 Browser

Chrome

🧱 Your Environment

No response

✅ Proposed Solution

No response

👀 Have you spent some time to check if this issue has been raised before?

  • [x] I checked and didn't find any similar issue

🏢 Have you read the Code of Conduct?

012git012 avatar Sep 26 '25 11:09 012git012

@prakarsh-dt @vikramdevtron please confirm that you have seen our comment in the advisories. One of the vulnerabilities is still reproducible. We kindly ask you to revisit the vulnerability and publish the advisories.

012git012 avatar Oct 03 '25 16:10 012git012

Hi @012git012, you must be a member of the organization 'devtron-labs' to add or remove labels.

systemsdt avatar Oct 03 '25 16:10 systemsdt

Hello @prakarsh-dt @012git012, We would like to bring this issue to your attention once again, as we are still awaiting your response.

012git012 avatar Nov 01 '25 09:11 012git012

Hi @012git012, you must be a member of the organization 'devtron-labs' to add or remove labels.

systemsdt avatar Nov 01 '25 09:11 systemsdt