Take Over the Whole Cluster: Attacking Kubernetes via Excessive Permissions of Third-party Applications

Nanzi Yang, Wenbo Shen, Jinku Li, Xunqi Liu, Xin Guo, Jianfeng Ma. Take Over the Whole Cluster: Attacking Kubernetes via Excessive Permissions of Third-party Applications. In Weizhi Meng 0001, Christian Damsgaard Jensen, Cas Cremers, Engin Kirda, editors, Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security, CCS 2023, Copenhagen, Denmark, November 26-30, 2023. pages 3048-3062, ACM, 2023. [doi]

@inproceedings{YangSLLGM23,
  title = {Take Over the Whole Cluster: Attacking Kubernetes via Excessive Permissions of Third-party Applications},
  author = {Nanzi Yang and Wenbo Shen and Jinku Li and Xunqi Liu and Xin Guo and Jianfeng Ma},
  year = {2023},
  doi = {10.1145/3576915.3623121},
  url = {https://doi.org/10.1145/3576915.3623121},
  researchr = {https://researchr.org/publication/YangSLLGM23},
  cites = {0},
  citedby = {0},
  pages = {3048-3062},
  booktitle = {Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security, CCS 2023, Copenhagen, Denmark, November 26-30, 2023},
  editor = {Weizhi Meng 0001 and Christian Damsgaard Jensen and Cas Cremers and Engin Kirda},
  publisher = {ACM},
}