Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Issue: plugin leaks hostnames unencrypted to 3P/WAN #263

Closed
sneak opened this issue Feb 12, 2020 · 1 comment
Closed

Security Issue: plugin leaks hostnames unencrypted to 3P/WAN #263

sneak opened this issue Feb 12, 2020 · 1 comment

Comments

@sneak
Copy link

sneak commented Feb 12, 2020

Creating another issue to track the security bug (data leak) that is a consequence of #193.

When using plugins/docker for builds, the internal docker setup sends DNS requests from the build unencrypted to Google's DNS servers at 8.8.8.8 and 8.8.4.4. This is a security bug, as it tells your ISP and anyone else listening what hostnames you are looking up!

@sneak sneak changed the title Security Issue: plugin leaks hostnames unencrypted to WAN Security Issue: plugin leaks hostnames unencrypted to 3P/WAN Feb 12, 2020
@ashwilliams1
Copy link

closing as duplicate of #193

@drone-plugins drone-plugins locked and limited conversation to collaborators Feb 12, 2020
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants