Source |
The Hacker News |
Identifiant |
8430294 |
Date de publication |
2023-12-28 18:50:00 (vue: 2023-12-28 14:07:46) |
Titre |
Google Cloud résout l'escalade du privilège Flaw impactant le service Kubernetes Google Cloud Resolves Privilege Escalation Flaw Impacting Kubernetes Service |
Texte |
Google Cloud a abordé un défaut de sécurité de la sévérité moyenne dans sa plate-forme qui pourrait être maltraité par un attaquant qui a déjà accès à un cluster Kubernetes pour augmenter ses privilèges.
"Un attaquant qui a compromis le conteneur & nbsp; bit Cluent & nbsp; journalisation pourrait combiner cet accès avec des privilèges élevés requis par & nbsp; Anthos Service Mesh & nbsp; (sur des clusters qui l'ont permis) à
Google Cloud has addressed a medium-severity security flaw in its platform that could be abused by an attacker who already has access to a Kubernetes cluster to escalate their privileges.
"An attacker who has compromised the Fluent Bit logging container could combine that access with high privileges required by Anthos Service Mesh (on clusters that have enabled it) to |
Notes |
★★★
|
Envoyé |
Oui |
Condensat |
abused access addressed already attacker bit logging by anthos cloud cluster clusters combine compromised container could enabled escalate escalation flaw google has have high impacting its kubernetes medium mesh platform privilege privileges required resolves security service severity the fluent who |
Tags |
Cloud
|
Stories |
|
Move |
|