wiz-sec / open-cvdb

An open project to list all publicly known cloud vulnerabilities and CSP security issues
https://cloudvulndb.org
Creative Commons Attribution 4.0 International
297 stars 59 forks source link

[Contribution] Sys:All #279

Open korniko98 opened 5 months ago

korniko98 commented 5 months ago

Summary (give a brief description of the issue)

The system:authenticated group in GKE includes anyone with a Google account, and could be assigned to cluster admin.

References (provide links to blogposts, etc.)

https://orca.security/resources/blog/sys-all-google-kubernetes-engine-risk/