fix(kubernetes): reject exec auth in cloud kubeconfigs (#11753)

This commit is contained in:
Hugo Pereira Brito
2026-07-07 09:57:46 +01:00
committed by GitHub
parent 6cae37174c
commit ad04e69c35
10 changed files with 273 additions and 4 deletions
+3
View File
@@ -24,6 +24,7 @@ All notable changes to the **Prowler API** are documented in this file.
### 🔐 Security
- User profile updates now allow users to update their own account while requiring user-management permissions to update other users in the same tenant [(#11792)](https://github.com/prowler-cloud/prowler/pull/11792)
- Kubernetes provider credentials now reject kubeconfigs using `exec` authentication in Prowler Cloud, preventing user-supplied commands from running on Cloud workers [(#11753)](https://github.com/prowler-cloud/prowler/pull/11753)
---
@@ -44,6 +45,8 @@ All notable changes to the **Prowler API** are documented in this file.
- Attack Paths: Provider graph cleanup now deletes Neo4j and Neptune relationships in directed batches before deleting nodes [(#11755)](https://github.com/prowler-cloud/prowler/pull/11755)
- `scan-perform` no longer reports an error when a provider is deleted during a running scan [(#11696)](https://github.com/prowler-cloud/prowler/pull/11696)
---
## [1.32.1] (Prowler v5.31.1)
### 🐞 Fixed