Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

POC Details: ccb4e6723291b64c8a879da06c77e89e02243223

Source
Associated Vulnerability

Likely 0-day

Description
Detects Kubernetes ClusterRoles that grant GET permission on nodes/proxy resource.
Due to an authorization inconsistency in Kubelet, the nodes/proxy GET permission allows
execution of commands in any container via WebSocket connections to the Kubelet API.
The Kubelet authorizes based on the initial HTTP GET method of WebSocket handshake
rather than the actual operation (exec/run/attach) which should require CREATE permission.
File Snapshot

id: k8s-clusterrole-nodes-proxy-rce info: name: ClusterRoles with Risky nodes/proxy GET Permissio ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.