RBAC Virtual Verbs: Teaching Kubernetes to Educate Dolphins
ID: 4ec310c2-76a4-5e88-a04a-78ca3a90be33
STIX ID: report--4ec310c2-76a4-5e88-a04a-78ca3a90be33
Feed Name: Aqua Security Blog
This report explains how Kubernetes RBAC uses string-equality checks for verbs and resources, allowing 'virtual verbs' (example: a custom 'educate' verb on a 'dolphin' CRD) and accepting unknown verbs/resources without server-side validation. It demonstrates the risk with examples and notes security-critical virtual verbs like 'impersonate', 'bind', and 'escalate', recommending that RBAC analysis tools account for dynamic resources and known virtual verbs and that operators be cautious of typos that can hide misconfigurations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
