services / Google Cloud / Kubernetes Engine Clusters

Manages Kubernetes clusters on Google Kubernetes Engine

One independent instance of a Kubernetes cluster, consisting of a node-pool and the Kubernetes objects such as deployments, statefulsets, pods, jobs that represents workloads and configuration running on the cluster, managed by Kubernetes.


container.​clusters.​deleteTagBinding

Tags can conditionally allow or deny IAM policies. Privilege escalation is possible since removing tags may lead to additional IAM bindings matching the principal.

Risks

Scope: CRITICAL

This privilege may grant access to sensitive data from a significant fraction of organizational functions, allow interruption of critical organizational services, or its exploit could lead to significant privilege escalation.

Contributed by P0 Security

© 2023–present P0 Security and contributors to the IAM Privilege Catalog