ConfigConfusion: one Kubernetes YAML grants GCP organization owner rights
Researcher Justin O'Leary disclosed ConfigConfusion: access to a namespace watched by Google Kubernetes Config Connector lets a user grant themselves any GCP role, including roles/owner on the whole organization, via an IAMPolicyMember resource. Google said KCC works as designed and the issue stems from administrator configuration.
- Attack needs only namespace access and permission to create IAMPolicyMember
- KCC executes requests with its own org-level service account
- Google calls KCC behavior by design and points to admin choices
- Root cause is the missing check between Kubernetes RBAC and Google Cloud IAM
Read next
Security