Vitess security audit
carried out a security audit of Vitess. The primary focus of the audit was a new component of Vitess, VTAdmin. The goal was to conduct a holistic security audit which includes multiple disciplines to consider end, the audit had the following high-level goals: 1. Formalise a threat model of VTAdmin. 2. Manually audit the VTAdmin code. 3. Manually audit the remaining Vitess code base. 4. Assess and improve Vitessʼs Users that can create keyspaces can deny access to already existing keyspaces” and “ADA-VIT-SA23-12, VTAdmin users that can create shards can deny access to other functions”. These two issues allowed a malicious0 码力 | 41 页 | 1.10 MB | 1 年前3The Vitess 11.0 Documentation
Component – Build/CI – Cluster Management – Java – Observability – Query Serving – VReplication – VTAdmin – vttestserver • Type – Announcement – Bug – CI/Build – Documentation – Enhancement – Feature Request0 码力 | 481 页 | 3.14 MB | 1 年前3The Vitess 12.0 Documentation
Component – Build/CI – Cluster Management – Java – Observability – Query Serving – VReplication – VTAdmin – vttestserver • Type – Announcement – Bug – CI/Build – Documentation – Enhancement – Feature Request0 码力 | 534 页 | 3.32 MB | 1 年前3
共 3 条
- 1