wiz-sec / open-cvdb

An open project to list all publicly known cloud vulnerabilities and CSP security issues
https://cloudvulndb.org
Creative Commons Attribution 4.0 International
303 stars 61 forks source link

[Contribution] GKE unauthorized access bugs #262

Open korniko98 opened 8 months ago

korniko98 commented 8 months ago

Summary (give a brief description of the issue)

Issues affecting the default configuration of GKE's logging agent FluentBit, which runs by default on all clusters, and the default privileges for Anthos Service Mesh (ASM), which is an optional add-on that customers can enable.

References (provide links to blogposts, etc.)

https://unit42.paloaltonetworks.com/google-kubernetes-engine-privilege-escalation-fluentbit-anthos/ https://cloud.google.com/anthos/clusters/docs/security-bulletins#gcp-2023-047