Azure / AKS

Azure Kubernetes Service
https://azure.github.io/AKS/
1.95k stars 305 forks source link

WireServing Defense in Depth #4503

Open miwithro opened 2 weeks ago

miwithro commented 2 weeks ago

The WireServing bug can be exploited by leveraging an AKS cluster that use the Azure CNI for network configuration and Azure network policy (NPM). The attack hinges on a TLS bootstrap attack targeting the tokens used for securely joining nodes to a Kubernetes cluster.

AKS Information In the 2024.07.16 Release Azure Container Networking updated the iptables rules in AKS clusters with Azure Network Policy Manager to block pod access to wireserver.

microsoft-github-policy-service[bot] commented 2 weeks ago

@miwithrow, @CocoWang-wql would you be able to assist?

miwithro commented 2 weeks ago

No customer action required.