2753 | Big Bugs: Bitbucket Pipelines Kata Containers Build Container Escape |
RCE |
NA |
Alex Chapman (@ajxchapman) |
Bug Bounty | 2021-02-28 | 2023-06-13 |
2747 | GKE Autopilot Node Compromise via local-storage PersistentVolume |
Container escape |
Google |
Anthony Weems |
Bug Bounty | 2021-03-01 | 2023-06-13 |
2739 | GKE Autopilot Node Compromise via startup-script |
Container escape |
Google |
Anthony Weems |
Bug Bounty | 2021-03-05 | 2023-06-13 |
2738 | GKE Autopilot Node Compromise via SSH Metadata |
Container escape |
Google |
Anthony Weems |
Bug Bounty | 2021-03-05 | 2023-06-13 |
2678 | GKE Autopilot Node Compromise via Race Condition |
Container escape |
Google |
Anthony Weems |
Bug Bounty | 2021-04-01 | 2023-06-13 |
2516 | runc mount destinations can be swapped via symlink-exchange to cause mounts outside the rootfs (CVE-2021-30465) |
Kubernetes
Container escape |
Google |
Etienne Champetier / champtar |
Bug Bounty | 2021-05-30 | 2023-06-13 |
2235 | Finding Azurescape – Cross-Account Container Takeover in Azure Container Instances |
Container takeover
Container escape
Privilege escalation
Cloud |
Microsoft |
Unit 42 (@Unit42_Intel) |
Bug Bounty | 2021-09-09 | 2023-06-13 |
1890 | CVE-2022-0185 - Winning a $31337 Bounty after Pwning Ubuntu and Escaping Google%27s KCTF Containers |
Container escape
Kubernetes bug |
Google |
Crusaders of Rust (@cor_ctf) |
Bug Bounty | 2022-01-25 | 2023-06-13 |
1756 | Container Escape to Shadow Admin: GKE Autopilot Vulnerabilities |
Privilege escalation
Container escape
Kubernetes |
Google |
Unit 42 (@Unit42_Intel) |
Bug Bounty | 2022-03-08 | 2023-06-13 |
1610 | AWS%27s Log4Shell Hot Patch Vulnerable to Container Escape and Privilege Escalation |
Privilege escalation
Container escape |
AWS |
Unit 42 (@Unit42_Intel) |
Bug Bounty | 2022-04-19 | 2023-06-13 |
1571 | Cloudflare Pages, part 1: The fellowship of the secret |
Command injection
Container escape
Bash Path injection
RCE
Local Privilege Escalation
Information disclosure |
Cloudflare |
Sean Yeoh (@seanyeoh) |
Bug Bounty | 2022-05-06 | 2023-06-13 |
1419 | FabricScape: Escaping Service Fabric and Taking Over the Cluster |
Container escape
Local Privilege Escalation
Cross-tenant vulnerability |
Microsoft |
Unit 42 (@Unit42_Intel) |
Bug Bounty | 2022-06-28 | 2023-06-13 |
1278 | Symlinks as mount portals: Abusing container mount points on MikroTik%27s RouterOS to gain code execution |
Container escape
Local Privilege Escalation |
MikroTik |
nns |
Bug Bounty | 2022-08-05 | 2023-06-13 |
1058 | Securing Developer Tools: OneDev Remote Code Execution |
RCE
SSRF
Broken Access Control
Container escape |
OneDev |
Paul Gerste |
Bug Bounty | 2022-09-20 | 2023-06-13 |
1046 | Exploiting Distroless Images |
Command injection
Arbitrary file read
Arbitrary file write
Container escape |
Google |
Daniel Teixeira (@TheRedOperator) |
Bug Bounty | 2022-09-22 | 2023-06-13 |
419 | Taking over “Google Cloud Shell” by utilizing capabilities and Kubelet |
Container escape
RCE
Kubernetes |
NA |
Chen Shiri (@ChenShiri73) |
Bug Bounty | 2023-02-21 | 2023-06-13 |
270 | Escalating Privileges with Azure Function Apps |
Privilege escalation
Cloud
Container escape
RCE |
Microsoft (Azure) |
Karl Fosaaen (@kfosaaen) |
Bug Bounty | 2023-03-23 | 2023-06-13 |
182 | #BrokenSesame: Accidental write’ permissions to private registry allowed potential RCE to Alibaba Cloud Database Services |
Cloud
RCE
Container escape
Kubernetes
Privilege escalation
Lateral movement
Supply chain attack
Cross-tenant vulnerability |
Alibaba |
Ronen Shustin (@ronenshh) |
Bug Bounty | 2023-04-19 | 2023-06-13 |
64 | Red team: Journey from RCE to have total control of cloud infrastructure |
RCE
SSTI
Container escape
Kubernetes
Components with known vulnerabilities
CI/CD |
NA |
Quang Vo (@mr_r3bot) |
Bug Bounty | 2023-05-22 | 2023-06-13 |
30 | AWS Chain Attack- Thousands of Vulnerable EKS Clusters |
AWS Kubernetes
EKS
Container escape
Security misconfiguration |
NA |
Chen Shiri (@ChenShiri73) |
Bug Bounty | 2023-06-04 | 2023-06-13 |