G Graphene OS News Mobile security, privacy, Android hardening, and open-source ecosystem news.
Log in Register Editor
EN RU DE PL ES
Back to latest

Security / BleepingComputer

How One Kubernetes YAML Can Hand Over a GCP Organization

1 min read

A Kubernetes user with limited permissions can potentially gain control of an entire Google Cloud organization by exploiting the authority granted to Google Kubernetes Config Connector. Varonis explains how this confused deputy problem can turn a single Kubernetes YAML file into a path to organization-wide privilege es...

A Kubernetes user with limited permissions can potentially gain control of an entire Google Cloud organization by exploiting the authority granted to Google Kubernetes Config Connector. Varonis explains how this confused deputy problem can turn a single Kubernetes YAML file into a path to organization-wide privilege es...

This portal shows a short summary and attribution. Follow the original source for the complete article.

Open original source