Zhitao Li created MESOS-8909:
--------------------------------

             Summary: Scrubbing value secret from HTTP responses
                 Key: MESOS-8909
                 URL: https://issues.apache.org/jira/browse/MESOS-8909
             Project: Mesos
          Issue Type: Task
          Components: security
            Reporter: Zhitao Li


Mesos supports a value based secret. However, I believe some HTTP endpoints and 
v1 operator responses could leak this information.

The goal here is to make sure these endpoints do not leak the information.

We did some quick research and gather the following list in this [Google 
doc|https://docs.google.com/document/d/1W26RUpYEB92eTQYbACIOem5B9hzXX59jeEIT9RB2X1o/edit#heading=h.gzvg4ec6wllm].



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)

Reply via email to