Post-Exploitation Identity Misuse in SPIFFE/SPIRE

Post-Exploitation Identity Misuse in SPIFFE/SPIRE

SPIFFE/SPIRE metadata is being exploited to spoof identities on co-located workloads in a post-exploitation attack on a compromised Kubernetes node.

Bottom line: Security teams must implement strict access controls and monitoring to prevent identity spoofing on Kubernetes clusters.

What's happening: On February 12, 2023, a vulnerability (CVE-2022-2658) in the Kubernetes component, cri-o, allowed an attacker with root access to a compromised node to exploit SPIFFE/SPIRE metadata and spoof identities on co-located workloads.

What to do: Security teams should review and update their Kubernetes cluster configurations to restrict access to SPIFFE/SPIRE metadata and implement regular monitoring to detect potential identity spoofing attacks.

Source: Unit 42