Security News > 2020 > January > Public Bug Bounty Program Launched for Kubernetes

Public Bug Bounty Program Launched for Kubernetes
2020-01-15 18:18

The Cloud Native Computing Foundation this week announced the launch of a public bug bounty program for Kubernetes, with rewards of up to $10,000 per vulnerability.

It was originally developed by Google and it's now maintained by the CNCF. The new bug bounty program is hosted by HackerOne and CNCF says it will do its best to respond to submitted reports within one business day, triage vulnerabilities within 10 days, and pay out a bounty within 10 days from triage.

Bounties range between $100 and $10,000, with the highest rewards being offered for vulnerabilities affecting the Kubernetes core, flaws that can be exploited to alter source code, and DoS attacks on release artifacts.

According to CNCF, the bug bounty program is managed by the Kubernetes Product Security Committee, whose members include representatives of Google, Red Hat and Shopify.

The launch of the bug bounty project comes just months after the completion of a security audit that led to the discovery of some critical vulnerabilities.


News URL

http://feedproxy.google.com/~r/Securityweek/~3/NuHdei77xn4/public-bug-bounty-program-launched-kubernetes

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Kubernetes 19 5 45 34 8 92