Dec 052018
 

A critical flaw in the Kubernetes container orchestration system has been announced. It will allow any user to compromise a Kubernetes cluster by way of exploiting any aggregated API server that is deployed for it. This affects all Kubernetes versions 1.0 to 1.12, but is only fixed in the supported versions (in 1.10.11, 1.11.5, and 1.12.3). “With a specially crafted request, users that are authorized to establish a connection through the Kubernetes API server to…

External feed Read More at the Source: https://lwn.net/Articles/773836/rss

 2018-12-05  Comments Off on Critical Kubernetes privilege escalation disclosed LWN.net