Dashboard

The Kubernetes Dashboard acts with a service account. Older deployments shipped it bound to a very privileged account and allowed skipping login, so anyone who reached the UI inherited that power: reading secrets and creating workloads across the cluster through a browser.

bash
# Find an exposed dashboard
curl -sk https://<host>/ | grep -i dashboard
# Legacy deployments expose a privileged service account; its token is in a secret
kubectl -n kubernetes-dashboard get secret -o name | grep dashboard

Exploitation notes#

  • The impact is whatever the dashboard's service account holds; the classic misconfiguration is cluster-admin plus skip-login.
  • Even with login required, the dashboard's own token (recoverable from its secret via another foothold) grants that account's rights.
  • Creating a pod through the dashboard that mounts the host or runs privileged turns UI access into Pod escape to node.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more