Kubernetes Capsule Vulnerability Enables Attackers to Inject Arbitrary Labels

Vulnerability Discovered in Kubernetes Capsule

Date: October 2023

Overview

Researchers have identified a significant vulnerability in Kubernetes Capsule versions v0.10.3 and earlier. This flaw enables authenticated tenant users to inject arbitrary labels into the system.

Implications

The ability to inject arbitrary labels poses a security risk, as it can lead to unauthorized access or manipulation of resources within the Kubernetes environment.

<footer