How One Kubernetes YAML Can Hand Over a GCP Organization
A Kubernetes user with limited permissions can potentially gain control of an entire Google Cloud organization by exploiting the authority granted to Google Kubernetes Config Connector. Varonis explains how this confused deputy problem can turn a single Kubernetes YAML file into a path to organization-wide privilege escalation. [...]
Contenu original affiche; la traduction localisee n'est pas encore disponible.
Ce qui s'est passé
A Kubernetes user with limited permissions can potentially gain control of an entire Google Cloud organization by exploiting the authority granted to Google Kubernetes Config Connector. Varonis explains how this confused deputy problem can turn a single Kubernetes YAML file into a path to organization-wide privilege escalation. [...]
Pourquoi c'est important
The incident may affect operational continuity, asset safety or trust around Google. Watch for verified scope and remediation.
Entités concernées
Voir les preuves
1 articles · 1 publication d'origine · 1 independantes
- BleepingComputerSource primaire · Confirme · EN · 100%How One Kubernetes YAML Can Hand Over a GCP Organization ↗
Affirmations
- How One Kubernetes YAML Can Hand Over a GCP Organization Observé
Divergences
Aucune divergence importante détectée dans les preuves disponibles.
Chronologie
- Premier signalement
Mouvement de marché suivant l'événement
La réaction du marché n'est pas encore disponible pour cet actif et cette fenêtre.