Understanding Resource Injection Vulnerabilities in Kubernetes Ecosystems
Defang Bo, Jie Lu, Feng Li, Jingting Chen, Jinchen Wang, Chendong Yu, Yeting Li, Wei Huo
摘要
Cloud-native technologies have revolutionized application development, with Kubernetes emerging as the de facto standard platform for containerization and orchestration. Kubernetes manages applications through API objects called resources, where users declare desired states via resource definitions that are processed by controllers to reconcile system discrepancies. However, this resource-based architecture introduces resource injection vulnerabilities, where controllers perform privileged operations using user-controllable fields without adequate validation. Attackers can exploit these weaknesses by injecting malicious content into resource fields to achieve unauthorized access and privilege escalation.In this paper, we conduct the first comprehensive study on 125 resource injection vulnerabilities from 8,306 Kubernetes-related vulnerabilities across common databases. For all studied vulnerabilities, we investigate their vulnerable fields, root causes, privileged operations, exploitation conditions, and fixing strategies. Our study reveals many interesting findings that can guide the detection and mitigation of resource injection vulnerabilities, as well as the development of more secure cloud-native applications.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- Dangers Behind Access Control: Understanding and Exploiting Implicit Permissions in KubernetesNanzi Yang, Xingyu Liu, Wenbo Shen, Jinku Li 等CCS 2025
- Breaking the Bulkhead: Demystifying Cross-Namespace Reference Vulnerabilities in Kubernetes OperatorsAndong Chen, Ziyi Guo, Zhaoxuan Jin, Zhenyuan Li 等NDSS 2026 · 被引用 2 次
- An Empirical Study on Kubernetes Operator BugsQingxin Xu, Yu Gao, Jun WeiISSTA 2024 · 被引用 7 次
- An Empirical Study and Benchmark of Kubernetes Misconfiguration ScannersHaeun Eom, Bohyun Suk, Sungjae HwangISSTA 2026
- Take Over the Whole Cluster: Attacking Kubernetes via Excessive Permissions of Third-party ApplicationsNanzi Yang, Wenbo Shen, Jinku Li, Xunqi Liu 等CCS 2023 · 被引用 15 次
