Security: clastix/kamaji
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
SQL injection via unescaped datastore identifier (DataStoreUsername/DataStoreSchema) in PostgreSQL/MySQL driversGHSA-r47v-ppwp-fh4r published
Jul 15, 2026 by prometherionModerate -
TenantControlPlane namespace/name collision binds two tenants to the same etcd key prefix, or SQL datastore schema + DB user, breaking per-tenant isolationGHSA-4f3f-65vx-r34f published
Jul 14, 2026 by prometherionHigh -
RBAC Roles for `etcd` created by Kamaji are not disjunctGHSA-6r4j-4rjc-8vw5 published
Aug 12, 2024 by prometherionHigh