Lune

CCS2025顶会

Dangers Behind Access Control: Understanding and Exploiting Implicit Permissions in Kubernetes

Nanzi Yang, Xingyu Liu, Wenbo Shen, Jinku Li, Kangjie Lu

2025年份

摘要

As the de-facto standard for container orchestration, Kubernetes is extensively adopted by numerous companies and cloud vendors, making its security critical. In this paper, we define a new attack surface called implicit permission: The execution of explicitly granted permissions in Kubernetes dynamically leads to implicit operations on other resources, enabling new permissions beyond the explicitly granted ones. Such implicit permissions create security vulnerabilities that attackers can exploit to compromise an entire cluster.

问问这篇 Paper

问问你的智能体。

Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。

可以从这些问题问起

智能体调用

Lunesearch_papers

在 Lune 里问

免费开始,无需绑卡

lune papers get 5a8a8c2f-e678-4ea1-891d-60ff26486df9

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖