Google Cloud behebt Fehler bei der Eskalation von Privilegien, der den Kubernetes-Dienst betrifft

Teilen:

Google Cloud has addressed a medium-severity security flaw in its platform that could be abused by an attacker who already has access to a Kubernetes cluster to escalate their privileges.

“An attacker who has compromised the Fluent Bit logging container could combine that access with high privileges required by Anthos Service Mesh (on clusters that have enabled it) to escalate privileges in the cluster,” the company said as part of an advisory released on December 14, 2023.

Palo Alto Networks Unit 42, which discovered and reported the shortcoming, said adversaries could weaponize it to carry out “data theft, deploy malicious pods, and disrupt the cluster’s operations.”

There is no evidence that the issue has been exploited in the wild. It has been addressed in the following versions of Google Kubernetes Engine (GKE) and Anthos Service Mesh (ASM) –

  • 1.25.16-gke.1020000
  • 1.26.10-gke.1235000
  • 1.27.7-gke.1293000
  • 1.28.4-gke.1083000
  • 1.17.8-asm.8
  • 1.18.6-asm.2
  • 1.19.5-asm.4

A key prerequisite to successfully exploiting the vulnerability hinges on an attacker having already compromised a FluentBit container by some other initial access methods, such as via a remote code execution flaw.

Google Cloud

“GKE uses Fluent Bit to process logs for workloads running on clusters,” Google elaborated. “Fluent Bit on GKE was also configured to collect logs for Cloud Run workloads. The volume mount configured to collect those logs gave Fluent Bit access to Kubernetes service account tokens for other Pods running on the node.”

This meant that a threat actor could use this access to gain privileged access to a Kubernetes cluster that has ASM enabled and then subsequently use ASM’s service account token to escalate their privileges by creating a new pod with cluster-admin privileges.

“The clusterrole-aggregation-controller (CRAC) service account is probably the leading candidate, as it can add arbitrary permissions to existing cluster roles,” security researcher Shaul Ben Hai said. “The attacker can update the cluster role bound to CRAC to possess all privileges.”

By way of fixes, Google has removed Fluent Bit’s access to the service account tokens and re-architected the functionality of ASM to remove excessive role-based access control (RBAC) permissions.

“Cloud vendors automatically create system pods when your cluster is launched,” Ben Hai concluded. “They are built in your Kubernetes infrastructure, the same as add-on pods that have been created when you enable a feature.”

“This is because cloud or application vendors typically create and manage them, and the user has no control over their configuration or permissions. This can also be extremely risky since these pods run with elevated privileges.”

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
11:36 am, Juni 21, 2025
Wetter-Symbol 30°C
L: 28° | H: 31°
aufgelockerte Bewölkung
Luftfeuchtigkeit: 41 %
Druck: 1017 mb
Wind: 11 mph SE
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 30%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:43 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
28° | 31°°C 0 mm 0% 10 mph 41 % 1017 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
18° | 26°°C 0.76 mm 76% 15 mph 75 % 1014 mb 0 mm/h
Mo. Juni 23 10:00 pm
Wetter-Symbol
15° | 24°°C 0.2 mm 20% 14 mph 82 % 1015 mb 0 mm/h
Di. Juni 24 10:00 pm
Wetter-Symbol
13° | 25°°C 0 mm 0% 15 mph 79 % 1016 mb 0 mm/h
Mi. Juni 25 10:00 pm
Wetter-Symbol
16° | 26°°C 0.34 mm 34% 12 mph 87 % 1011 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
29° | 30°°C 0 mm 0% 10 mph 41 % 1017 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
30° | 31°°C 0 mm 0% 7 mph 37 % 1017 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
26° | 27°°C 0 mm 0% 7 mph 35 % 1015 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
24° | 24°°C 0 mm 0% 9 mph 34 % 1013 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
20° | 20°°C 0.76 mm 76% 8 mph 57 % 1013 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
20° | 20°°C 0.2 mm 20% 9 mph 75 % 1013 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
18° | 18°°C 0 mm 0% 10 mph 65 % 1014 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
23° | 23°°C 0 mm 0% 12 mph 46 % 1014 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€90,171.42
-1.98%
Ethereum(ETH)
€2,118.66
-4.35%
Fesseln(USDT)
€0.87
0.00%
XRP(XRP)
€1.86
-1.38%
Solana(SOL)
€123.42
-4.02%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.142187
-3.87%
Shiba Inu(SHIB)
€0.000010
-2.90%
Pepe(PEPE)
€0.000009
-3.44%
Peanut das Eichhörnchen(PNUT)
€0.218233
13.10%
Nach oben scrollen