Lune

CCS2025Top-tier venue

Dangers Behind Access Control: Understanding and Exploiting Implicit Permissions in Kubernetes

Nanzi Yang, Xingyu Liu, Wenbo Shen, Jinku Li, Kangjie Lu

2025Year

Abstract

As the de-facto standard for container orchestration, Kubernetes is extensively adopted by numerous companies and cloud vendors, making its security critical. In this paper, we define a new attack surface called implicit permission: The execution of explicitly granted permissions in Kubernetes dynamically leads to implicit operations on other resources, enabling new permissions beyond the explicitly granted ones. Such implicit permissions create security vulnerabilities that attackers can exploit to compromise an entire cluster.

Ask about this paper

Ask your agent about it.

Lune has read the top-tier papers around this one, so every answer names the papers it rests on.

Questions to start from

Your agent calls

Lunesearch_papers

Ask in Lune

Free to start. No credit card required.

lune papers get 5a8a8c2f-e678-4ea1-891d-60ff26486df9

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines