Kubernetes Dashboard before 1.10.1 allows attackers to bypass authentication and use Dashboard's Service Account for reading secrets within the cluster.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
https://sysdig.com/blog/privilege-escalation-kubernetes-dashboard/ | third party advisory exploit |
http://www.securityfocus.com/bid/106493 | vdb entry third party advisory |
https://groups.google.com/forum/#%21topic/kubernetes-announce/yBrFf5nmvfI | |
https://github.com/kubernetes/dashboard/releases/tag/v1.10.1 | third party advisory release notes |
https://github.com/kubernetes/dashboard/pull/3400 | third party advisory patch |
https://github.com/kubernetes/dashboard/pull/3289 | third party advisory patch |