How One Kubernetes YAML Can Hand Over a GCP Organization
Read original article ↗AI Summary
A security vulnerability dubbed 'ConfigConfusion' allows attackers with access to a Kubernetes namespace to escalate privileges and gain full control of a Google Cloud (GCP) organization by exploiting misconfigurations in Google Kubernetes Config Connector (KCC). KCC uses a single, highly privileged service account to manage cloud resources on behalf of developers, but does not validate whether the requesting user has appropriate Google Cloud IAM permissions. As a result, an attacker can submit a malicious IAMPolicyMember YAML resource to grant themselves owner-level access to the entire GCP organization, even without possessing any cloud credentials. This represents a confused deputy problem where KCC acts as an overprivileged intermediary.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.