Take Over the Whole Cluster: Attacking Kubernetes via Excessive Permissions of Third-party Applications
Nanzi Yang, Wenbo Shen, Jinku Li, Xunqi Liu, Xin Guo, Jianfeng Ma
摘要
As the dominant container orchestration system, Kubernetes is widely used by many companies and cloud vendors. It runs thirdparty add-ons and applications (termed third-party apps) on its control plane to manage the whole cluster. The security of these third-party apps is critical to the whole cluster but has not been systematically studied so far. Therefore, this paper analyzes the security of third-party apps and reveals that third-party apps are granted excessive critical permissions, which can be exploited by an attacker to escape from the worker node and take over the whole Kubernetes cluster. Even worse, excessive permissions of different third-party apps can be chained together to turn non-critical issues into severe attack vectors. To systematically analyze the exploitability of excessive permissions, we design three strategies based on different attacking paths. These three strategies can steal the cluster admin permission with the DaemonSet of a third-party app directly, or via the same app's or another app's critical component indirectly. We investigate the security impact of excessive permission attacks in real production environments. We analyze all third-party apps in CNCF and show that 51 of 153 (33.3%) ones have potential security risks. We further scan Kubernetes services provided by the top four cloud vendors. The results show that all of them are vulnerable to excessive permission attacks. We report all our findings to the corresponding teams and get eight new CVEs from communities and a security bounty from Google. CCS CONCEPTS • Security and privacy → Distributed systems security.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Bugs in Pods: Understanding Bugs in Container Runtime SystemsJiongchi Yu, Xiaofei Xie, Cen Zhang, Sen Chen 等ISSTA 2024 · 被引用 3 次
- Breaking the Bulkhead: Demystifying Cross-Namespace Reference Vulnerabilities in Kubernetes OperatorsAndong Chen, Ziyi Guo, Zhaoxuan Jin, Zhenyuan Li 等NDSS 2026 · 被引用 2 次
- EPScan: Automated Detection of Excessive RBAC Permissions in Kubernetes ApplicationsYue Gu, Xin Tan, Yuan Zhang, Siyan Gao 等S&P 2025
它引用的顶会 Paper8
- The Feasibility of Dynamically Granted Permissions: Aligning Mobile Privacy with User PreferencesPrimal Wijesekera, Arjun Baokar, Lynn Tsai, Joel Reardon 等S&P 2017 · 被引用 156 次
- Security Namespace: Making Linux Security Frameworks Available to ContainersYuqiong Sun, David Safford, Mimi Zohar, Dimitrios Pendarakis 等USENIX Security 2018 · 被引用 79 次
- BASTION: A Security Enforcement Network Stack for Container NetworksJaehyun Nam, Seungsoo Lee, Hyunmin Seo, Phil Porras 等USENIX ATC 2020 · 被引用 55 次
- Can Systems Explain Permissions Better? Understanding Users' Misperceptions under Smartphone Runtime Permission ModelBingyu Shen, Lili Wei, Chengcheng Xiang, Yudong Wu 等USENIX Security 2021 · 被引用 45 次
- Harvesting Inconsistent Security Configurations in Custom Android ROMs via Differential AnalysisYousra Aafer, Xiao Zhang, Wenliang DuUSENIX Security 2016 · 被引用 43 次
相关 Paper
- Dangers Behind Access Control: Understanding and Exploiting Implicit Permissions in KubernetesNanzi Yang, Xingyu Liu, Wenbo Shen, Jinku Li 等CCS 2025
- Cross Container Attacks: The Bewildered eBPF on CloudsYi He, Roland Guo, Yunlong Xing, Xijia Che 等USENIX Security 2023
- Hazard Integrated: Understanding Security Risks in App Extensions to Team Chat SystemsMingming Zha, Jice Wang, Yuhong Nan, Xiaofeng Wang 等NDSS 2022
- Credit Karma: Understanding Security Implications of Exposed Cloud Services through Automated Capability InferenceXueqiang Wang, Yuqiong Sun, Susanta Nanda, XiaoFeng WangUSENIX Security 2023
- Understanding Resource Injection Vulnerabilities in Kubernetes EcosystemsDefang Bo, Jie Lu, Feng Li, Jingting Chen 等ASE 2025
