Skip to main content

Tag: configconfusion

2 articles

Technicians work in a brightly-lit data center with rows of server racks and monitoring screens, with a blank laptop screen…

Kubernetes Flaw Exposes GCP Organizations to Privilege Escalation

Google downplays a Kubernetes flaw dubbed ConfigConfusion, which researchers say could allow privilege escalation in GCP organizations, as simply "working as designed" despite concerns from the security community. The issue arises from a handoff in authority between GitOps and Google Kubernetes Config Connector.

Analyst 207
Kubernetes management interface on a laptop screen in a data center background.

Google Exposes Flaw in Kubernetes Operator, Denies Bug Bounty

Google's security team initially praised researcher Justin O'Leary for uncovering a high-severity flaw, dubbed ConfigConfusion, in the Config Connector add-on for Kubernetes - only to later claim it wasn't a vulnerability at all and deny a bug bounty. The issue still lingers, leaving users of the open-source tool potentially exposed.

Analyst 207