Tag: configconfusion
2 articles

Kubernetes Flaw Exposes GCP Organizations to Privilege Escalation
Google downplays a Kubernetes flaw dubbed ConfigConfusion, which researchers say could allow privilege escalation in GCP organizations, as simply "working as designed" despite concerns from the security community. The issue arises from a handoff in authority between GitOps and Google Kubernetes Config Connector.

Google Exposes Flaw in Kubernetes Operator, Denies Bug Bounty
Google's security team initially praised researcher Justin O'Leary for uncovering a high-severity flaw, dubbed ConfigConfusion, in the Config Connector add-on for Kubernetes - only to later claim it wasn't a vulnerability at all and deny a bug bounty. The issue still lingers, leaving users of the open-source tool potentially exposed.