Identity And Access
604 incident problems about Identity And Access. Start with the reviewed ones.
먼저 읽을 가이드
추천 문제
All problems (604)
SECURITY-1444A hardened proxy protects the main admin route and an internal DAV alias still permits writesA proxy looks hardened and a legacy authoring endpoint still accepts writes through one alias path.SecurityAdvanced13 minProSECURITY-1434A hardened proxy protects the main admin route and an internal DAV alias...A hardened proxy protects the main admin route and an internal DAV alias... focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Internal rewrites can bypass expected auth when named locations do not inhe...SecurityAdvanced13 minProSECURITY-1404A hardened reverse proxy blocks all normal verbs and still leaks file...A hardened reverse proxy blocks all normal verbs and still leaks file... focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Security gaps often hide in old HTTP methods that were never exercised during stan...SecurityAdvanced13 minProSECURITY-1328A private registry login is successful and image pulls still return 401A private registry login is successful and image pulls still return 401 focuses on Identity And Access and asks the reader to isolate the key signal in docker. Auth redirects across hosts can fail at cookie scope even when credentials and TLS are co...SecurityIntermediate13 minProSECURITY-1394An NGINX auth_request flow protects GET and POST and one WebDAV verb bypasses...An NGINX auth_request flow protects GET and POST and one WebDAV verb... focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Rare HTTP verbs often follow older location trees and can bypass newer auth subrequ...SecurityAdvanced13 minProSECURITY-1342An OpenSearch dashboard login loopsA proxy hardening change improves cookie posture and later dashboard users get trapped in a login redirect loop.SecurityIntermediate13 minProSECURITY-1338An OpenSearch Dashboards login loop appearsAn OpenSearch Dashboards login loop appears focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Modern cookie defaults can break older federated flows even when every credential and endpoint is correct.SecurityIntermediate13 minProSECURITY-1352An OpenSearch SSO redirect loop appears after proxy hardeningA reverse proxy is hardened and later users become trapped in a dashboard login loop even though the identity provider is healthy.SecurityIntermediate13 minProSECURITY-1316An SSH CA rollout signs host certificates correctly and engineers still get...An SSH CA rollout signs host certificates correctly and engineers still get... focuses on Identity And Access and asks the reader to isolate the key signal in Linux. SSH CA incidents often hide in stale host cert issuance rather t...SecurityIntermediate13 minProSECURITY-1396A Cilium egress deny policy appears tight and one init container still...A Cilium egress deny policy appears tight and one init container still... focuses on Identity And Access and asks the reader to isolate the key signal in Kubernetes. Short-lived container phases can expose timing windows that st...SecurityAdvanced14 minProSECURITY-1367A Cilium FQDN policy allows the configured hostname and still blocks trafficA service mesh is enabled and only name-based egress policy begins failing for one dependency path.SecurityAdvanced14 minProSECURITY-1391A Cloudflare Access application protects the dashboard and one API path stays...A Cloudflare Access application protects the dashboard and one API path... focuses on Identity And Access and asks the reader to isolate the key signal in Cloudflare. Machine-auth exceptions can unintentionally shadow user-facing policy when hos...SecurityAdvanced14 minProSECURITY-1326A GitHub package publish from Dependabot failsA GitHub package publish from Dependabot fails focuses on Identity And Access and asks the reader to isolate the key signal in GitHub. Different GitHub event types can carry meaningfully different token capabilities even inside one repos...SecurityAdvanced14 minProSECURITY-1351A Grafana login succeeds and team access disappearsAn SSO schema update lands and later Grafana users can log in but lose the permissions tied to their old team claim mapping.SecurityAdvanced14 minProSECURITY-1361A Grafana SSO login succeeds and folders vanishAn IdP schema update rolls out and later Grafana users can log in but lose access to the teams and folders they previously owned.SecurityAdvanced14 minProNETWORK-1369A pfSense HA pair syncs cleanly and one package VPN remains brokenAn HA firewall upgrade looks successful and later one package-managed VPN fails only after failover to the secondary node.NetworkAdvanced14 minProNETWORK-1359A pfSense HA sync reports success and one package VPN never returns on the...A pfSense HA sync reports success and one package VPN never returns on the... focuses on Identity And Access and asks the reader to isolate the key signal in netgate. HA success on the base firewall does not guarantee package-owned...NetworkAdvanced14 minProLINUX-1392A rootless container runtime works on one host and fails on anotherA rootless container runtime works on one host and fails on another focuses on Identity And Access and asks the reader to isolate the key signal in Linux. User namespace failures often come from host identity allocation conflicts rather than f...LinuxAdvanced14 minProSECURITY-1429A service binding receives a tighter policy and one app tier keeps old rightsA service binding receives a tighter policy and one app tier keeps old rights focuses on Cache Control and asks the reader to isolate the key signal in hashicorp. Authorization drift can survive policy rollout when apps only invalidate p...SecurityAdvanced14 minProSECURITY-1439A service binding receives a tighter policy and one app tier keeps old rightsA service binding receives a tighter policy and one app tier keeps old rights focuses on Cache Control and asks the reader to isolate the key signal in hashicorp. Authorization drift can survive policy rollout when pools refresh on...SecurityAdvanced14 minPro