google / tsunami-security-scanner-plugins

This project aims to provide a central repository for many useful Tsunami Security Scanner plugins.
Apache License 2.0
872 stars 176 forks source link

Kubernetes RCE via Open Access #346

Closed dawidg-doyen closed 10 months ago

dawidg-doyen commented 11 months ago

The plugin detects a Kubernetes service with anonymous access and attempts to execute arbitrary code by creating a new pod if excessive permissions have been added to the system:anonymous user.

maoning commented 10 months ago

@dawidg-doyen Look like there are some conflicts, could you do a rebase?

dawidg-doyen commented 10 months ago

I've just done a rebase. I can see "This branch has no conflicts with the base branch". Please let me know if there are any issues still. Thank you for the review.

maoning commented 10 months ago

Hi @dawidg-doyen,

Your PR has been merged. This usually means a reward will be granted. Google will start the internal QC process and the reward amount will be determined based on the quality of the detector report. Please be patient and allow up to a week for the QC process to finish. You'll be notified once the decision is made.

Thanks!