Security News > 2020 > May > Google Adds GKE Open-Source Dependencies to Vulnerability Rewards Program

Google Adds GKE Open-Source Dependencies to Vulnerability Rewards Program
2020-05-29 03:42

Google this week announced an expansion for its Vulnerability Rewards Program to include critical open-source dependencies of Google Kubernetes Engine.

The announcement builds on the bug bounty program for Kubernetes that the Cloud Native Computing Foundation, in partnership with Google and others, announced earlier this year, and which offers rewards of up to $10,000 for vulnerabilities in the project.

Google is now inviting bug hunters to find vulnerabilities in a lab environment that was set up on GKE based on kCTF, an open-source Kubernetes-based Capture-the-Flag project.

"Any vulnerabilities found outside of GKE should be reported to the corresponding upstream project security teams. To make this program expansion as efficient as possible for the maintainers, we will only reward vulnerabilities shown to be exploitable by stealing a flag," Google explains.

"By including the CTF infrastructure in the scope of the Google VRP, we want to incentivise the community to help us secure not just the CTF competitions that will use it, but also GKE and the broader Kubernetes ecosystems," Google notes.


News URL

http://feedproxy.google.com/~r/Securityweek/~3/5MD0A1afkCo/google-adds-gke-open-source-dependencies-vulnerability-rewards-program

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Google 102 253 4226 4525 728 9732