#BrokenSesame: Accidental ‘write’ permissions to private registry allowed potential RCE to Alibaba Cloud Database Services
ID: 2f75fd45-1197-5e2d-9900-bbd26750eead
STIX ID: report--2f75fd45-1197-5e2d-9900-bbd26750eead
Feed Name: Wiz Blog
Wiz Research disclosed “#BrokenSesame,” a chain of critical flaws in Alibaba Cloud’s managed PostgreSQL services that allowed privilege escalation inside containers, escape to the Kubernetes node, access to other tenants’ pods and data, and write access to the private container registry enabling a potential supply‑chain remote code execution. The blog details attack paths, root causes (namespace sharing, over‑privileged kubelet, non‑scoped registry credentials, secret leakage), and remediation steps taken by Alibaba Cloud after responsible disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
