Security researchers detail GCP privilege-escalation risk in Kubernetes Config Connector
Researchers describe how Google Kubernetes Config Connector (KCC), a GitOps controller used to manage Google Cloud resources from Kubernetes YAML files, can be manipulated through resources like IAMPolicyMember to escalate privileges. Because KCC authenticates to Google Cloud on behalf of developers using its own credentials, a maliciously crafted or overly permissive YAML file applied to a cluster could grant broad access across a Google Cloud organization.