A single Kubernetes YAML file could enable a Google Cloud organization takeover
BleepingComputer, citing Varonis in sponsored coverage, says Config Connector could let users with limited Kubernetes permissions gain organization-wide control.
TLDR
BleepingComputer’s sponsored coverage, citing Varonis, describe a potential “confused deputy” problem involving Google Kubernetes Config Connector. A user with limited namespace access could exploit the authority granted to the connector, turning a single Kubernetes YAML file into a path to control of an entire Google Cloud organization.
A single Kubernetes YAML file could enable a Google Cloud organization takeover
BleepingComputer, citing Varonis in sponsored coverage, says Config Connector could let users with limited Kubernetes permissions gain organization-wide control.
TLDR
BleepingComputer’s sponsored coverage, citing Varonis, describe a potential “confused deputy” problem involving Google Kubernetes Config Connector. A user with limited namespace access could exploit the authority granted to the connector, turning a single Kubernetes YAML file into a path to control of an entire Google Cloud organization.
