How One Kubernetes YAML Can Hand Over a GCP Organization

Config Connector (KCC) removes the need for developers to handle Google Cloud credentials by letting Kubernetes controllers manage resources on their behalf through GitOps. But if KCC has broad organization-level IAM permissions, a user with limited Kubernetes access can exploit the confused deputy flaw in ConfigConfusion to gain Google Cloud control. #ConfigConnector #KCC #ConfigConfusion #WorkloadIdentity #GoogleKubernetesEngine

Keypoints

  • KCC lets developers create Google Cloud resources through Kubernetes YAML without using cloud credentials.
  • ConfigConfusion abuses KCC’s organization-level service account to escalate privileges.
  • A user who can create IAMPolicyMember resources in a watched namespace can grant powerful IAM roles.
  • The issue comes from two separate authorization systems that do not verify the full request together.
  • Limiting KCC permissions and restricting IAM resource creation are key defenses.

Read More: https://www.bleepingcomputer.com/news/security/how-one-kubernetes-yaml-can-hand-over-a-gcp-organization/