Unfixable Kubernetes Security Hole Means Potential Man-in-the-Middle Attacks

if a hostile user can create a ClusterIP service and set the spec.externalIPs field, they can intercept traffic to that IP.  In addition, if a user can patch the status of a LoadBalancer service, they can also grab traffic. Now, the latter is a privileged operation and Joe and Jane User shouldn’t have that right, but, in practice, mistakes are made and it happens.

Read full article on The New Stack


