In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade skypilot to version 0.10.4 or higher.
skypilot is a SkyPilot: Run AI on Any Infra — Unified, Faster, Cheaper.
Affected versions of this package are vulnerable to Exposure of Data Element to Wrong Session in the form of allowing users to see the pending jobs belonging to other users, under some conditions, and leaking keys into an unintended config file. By not placing the user hash into the database at job queue time, the node exposes pending jobs to other uses. Additionally, keys belonging to a controller server are written into the API server config when it is started up. These keys may not be overwritten by subsequent request configs and may therefore be applied to unintended jobs.