Comment by treesknees
4 days ago
One where customers have their own scanners, and their unfounded panic overrides logical analysis by the engineers and admins.
We’ve had to patch plenty of stupid “security” bugs just to satisfy a paying customer.
4 days ago
One where customers have their own scanners, and their unfounded panic overrides logical analysis by the engineers and admins.
We’ve had to patch plenty of stupid “security” bugs just to satisfy a paying customer.
This is the real answer to the op.
It’s incredible how overblown these sorts of things can become
If the customer can run the scanner and find the vuln, that means they can log in, right? Which means they can RCE.
Not always, it can be run at static code analysis or the container repository (not the prod one)?