Describe the bug
Hi team, There has been an article posted online about how such permission can lead to potential RCE
https://grahamhelton.com/blog/nodes-proxy-rce
I found that we do have such permission here
|
- nodes/proxy |
|
verbs: |
|
- get |
Is it safe to just delete this permission without affecting the current functionality of NFD?
If it is safe to do so, I can follow up with a PR to delete it
To Reproduce
Expected behavior
Environment (please provide the following information):