3725 | In Cloud we “Trust”: Wrong Kubernetes implementation by Google Cloud Platform & Microsoft Azure affecting customers |
Old components with known vulnerabilities |
Microsoft
Google |
Chen Cohen (@chencococococo) |
Bug Bounty | 2020-01-12 | 2023-06-13 |
3430 | When it’s not only about a Kubernetes CVE… |
SSRF |
Microsoft |
Reever Zax (@ReeverZax) |
Bug Bounty | 2020-06-02 | 2023-06-13 |
2800 | I Own your Cloud Shell: Taking over “Azure Cloud Shell” Kubernetes Cluster Through Unsecured Kubelet API 30,000$ Bounty |
Privilege escalation
RCE |
Microsoft |
Chen Cohen (@chencococococo) |
Bug Bounty | 2021-02-15 | 2023-06-13 |
2760 | Host MITM attack via IPv6 rogue router advertisements (K8S CVE-2020-10749 / Docker CVE-2020-13401 / LXD / WSL2 / ...) |
MiTM |
Kubernetes |
Etienne Champetier / champtar |
Bug Bounty | 2021-02-28 | 2023-06-13 |
2759 | Kubernetes man in the middle using LoadBalancer or ExternalIPs (CVE-2020-8554) |
MiTM |
Kubernetes |
Etienne Champetier / champtar |
Bug Bounty | 2021-02-28 | 2023-06-13 |
2517 | Metadata service MITM allows root privilege escalation (EKS / GKE) |
Kubernetes
Privilege escalation
MiTM |
Google |
Etienne Champetier / champtar |
Bug Bounty | 2021-05-30 | 2023-06-13 |
2516 | runc mount destinations can be swapped via symlink-exchange to cause mounts outside the rootfs (CVE-2021-30465) |
Kubernetes
Container escape |
Google |
Etienne Champetier / champtar |
Bug Bounty | 2021-05-30 | 2023-06-13 |
2338 | CVE-2021-25738 |
RCE |
Kubernetes |
Jordy Versmissen / J0VSEC (@j0v0x0) |
Bug Bounty | 2021-08-07 | 2023-06-13 |
2031 | Exploring Container Security: A Storage Vulnerability Deep Dive |
Race condition
Kubernetes |
Kubernetes |
Fabricio Voznika |
Bug Bounty | 2021-12-02 | 2023-06-13 |
1890 | CVE-2022-0185 - Winning a $31337 Bounty after Pwning Ubuntu and Escaping Google%27s KCTF Containers |
Container escape
Kubernetes bug |
Google |
Crusaders of Rust (@cor_ctf) |
Bug Bounty | 2022-01-25 | 2023-06-13 |
1856 | Malicious Kubernetes Helm Charts can be used to steal sensitive information from Argo CD deployments |
Supply chain attack
CI/CD |
Argo CD |
Apiiro’s Security Research |
Bug Bounty | 2022-02-03 | 2023-06-13 |
1756 | Container Escape to Shadow Admin: GKE Autopilot Vulnerabilities |
Privilege escalation
Container escape
Kubernetes |
Google |
Unit 42 (@Unit42_Intel) |
Bug Bounty | 2022-03-08 | 2023-06-13 |
1548 | Kubernetes Privilege Escalation: Excessive Permissions in Popular Platforms |
Privilege escalation
Broken Access Control
Kubernetes |
Google
AWS
Microsoft
Red Hat |
Yuval Avrahami (@yuval_avrahami) |
Bug Bounty | 2022-05-17 | 2023-06-13 |
1511 | External Authentication bypass in ingress-nginx |
Path traversal
Authentication bypass |
Kubernetes |
Niemiec Marcin (@xvnpw) |
Bug Bounty | 2022-05-29 | 2023-06-13 |
1383 | Exploiting Authentication in AWS IAM Authenticator for Kubernetes |
Authentication flaw
Privilege escalation |
AWS |
Gafnit Amiga (@gafnitav) |
Bug Bounty | 2022-07-11 | 2023-06-13 |
419 | Taking over “Google Cloud Shell” by utilizing capabilities and Kubelet |
Container escape
RCE
Kubernetes |
NA |
Chen Shiri (@ChenShiri73) |
Bug Bounty | 2023-02-21 | 2023-06-13 |
182 | #BrokenSesame: Accidental write’ permissions to private registry allowed potential RCE to Alibaba Cloud Database Services |
Cloud
RCE
Container escape
Kubernetes
Privilege escalation
Lateral movement
Supply chain attack
Cross-tenant vulnerability |
Alibaba |
Ronen Shustin (@ronenshh) |
Bug Bounty | 2023-04-19 | 2023-06-13 |
97 | Container security: Infecting images to establish backdoors |
Container security
Kubernetes |
NA |
Emilien Socchi (@emiliensocchi) |
Bug Bounty | 2023-05-12 | 2023-06-13 |
64 | Red team: Journey from RCE to have total control of cloud infrastructure |
RCE
SSTI
Container escape
Kubernetes
Components with known vulnerabilities
CI/CD |
NA |
Quang Vo (@mr_r3bot) |
Bug Bounty | 2023-05-22 | 2023-06-13 |
30 | AWS Chain Attack- Thousands of Vulnerable EKS Clusters |
AWS Kubernetes
EKS
Container escape
Security misconfiguration |
NA |
Chen Shiri (@ChenShiri73) |
Bug Bounty | 2023-06-04 | 2023-06-13 |