Kubernetes Dashboard before 1.10.1 allows attackers to bypass authentication and use Dashboard's Service Account for reading secrets within the cluster.
No PoCs from references.
- https://github.com/20142995/nuclei-templates
- https://github.com/ARPSyndicate/kenzer-templates
- https://github.com/Elsfa7-110/kenzer-templates
- https://github.com/atwilsecurity/k8s-Security
- https://github.com/cloudnative-security/hacking-kubernetes
- https://github.com/d4n-sec/d4n-sec.github.io
- https://github.com/dli408097/k8s-security
- https://github.com/g3rzi/HackingKubernetes
- https://github.com/hacking-kubernetes/hacking-kubernetes.info
- https://github.com/magnologan/awesome-k8s-security
- https://github.com/rosyrut/K8S-Security
- https://github.com/sunilbennur/kubernetes-Security-master