Kubernetes Remote Code Execution via Nodes/Proxy Get Permission
grahamhelton.com
grahamhelton.com
That's rough
> The same behavior was fixed elsewhere
It is a problem, but in order to exploit it you need a valid token and have public kubelet endpoints or need to compromise an service within the cluster that has the required RBAC permissions. So cluster admins can cat and check their RBAC