Kubernetes YAML File Leads to Privilege Escalation in GCP Organizations
A recent discovery by Varonis highlights the potential risks associated with limited Kubernetes user permissions when combined with Google Kubernetes Config Connector.
Confused Deputy Problem Grants Control over GCP Organization
A Kubernetes user with restricted access can potentially exploit the authority granted by Google Kubernetes Config Connector, leading to a complete takeover of an entire Google Cloud organization.
Single YAML File Opens Path to Organization-Wide Privilege Escalation
A user's limited access in Kubernetes can result in a "confused deputy" problem, where a single YAML file can grant unauthorized access to a wide range of resources within a Google Cloud Platform (GCP) organization.
Google Cloud Platform Vulnerability: Limited Users Can Control Organization
A vulnerability in the Google Kubernetes Config Connector has led to concerns regarding the control a user with limited permissions can exert over a GCP organization. Varonis has shed light on the potential risks associated with this issue.
Kubernetes YAML File Opens Door to Organizational Takeover
A Kubernetes user with restricted access can potentially exploit the authority granted by Google Kubernetes Config Connector, resulting in the control of an entire Google Cloud organization through the manipulation of a single YAML file.
Google Cloud Platform Security Alert: YAML File Used for Privilege Escalation
A security alert has been issued regarding a potential threat to Google Cloud Platform security. A user with limited permissions can gain control over an organization by leveraging a Kubernetes YAML file and the confused deputy problem.
Kubernetes YAML File Threatens GCP Security: Limited Users Can Control Organization
A recent development in Kubernetes has raised concerns regarding the security of Google Cloud Platform. A user with restricted access can manipulate a single YAML file to gain unauthorized control over an entire GCP organization.
<small>Source: Bleeping Computer — read the original story there.</small>