Flaw discovered in Kubernetes lets any user gain full admin privileges on any compute node being run in a Kubernetes cluster; patched versions are available
A flaw has been detected in kubernetes … Mitch Wagner / Light Reading : Kubernetes Security Flaw Is a ‘Really Big Deal’ Patch Now James Orme / The Stack : Kubernetes security flaw allows hackers to infiltrate backend servers Sergiu Gatlan / Softpedia News : Kubernetes Patched to Address Critical Privilege Escalation Flaw Lucian Constantin / The New Stack : Critical Vulnerability Allows Kubernetes Node Hacking Ionut Ilascu / BleepingComputer : Kubernetes Updates Patch Critical Privilege Escalation Bug Tweets: Ashesh Badani / @asheshbadani : Some confusion around Kubernetes CVE so just to be clear, @openshift is providing patches back to v3.2 (based on Kube 1.2) which released in May 2016. That's the value of your @RedHat subscription. http://access.redhat.com/... Kenn White / @kennwhite : “access to all secrets, pods, environment variables, running pod/container processes, and persistent volumes [...] Additionally...vulnerability allows cluster-admin level access” http://access.redhat.com/...