mirror of
https://github.com/aquasecurity/kube-hunter.git
synced 2026-08-22 05:36:21 +00:00
24 lines
903 B
Markdown
24 lines
903 B
Markdown
---
|
|
vid: KHV003
|
|
title: Azure Metadata Exposure
|
|
categories: [Information Disclosure]
|
|
---
|
|
|
|
# {{ page.vid }} - {{ page.title }}
|
|
|
|
## Issue description
|
|
|
|
Microsoft Azure provides an internal HTTP endpoint that exposes information from the cloud platform to workloads running in a VM. The endpoint is accessible to every workload running in the VM. An attacker that is able to execute a pod in the cluster may be able to query the metadata service and discover additional information about the environment.
|
|
|
|
## Remediation
|
|
|
|
Starting in the 2020.10.15 Azure VHD Release, AKS restricts the pod CIDR access to that internal HTTP endpoint.
|
|
|
|
[CVE-2021-27075](https://github.com/Azure/AKS/issues/2168)
|
|
|
|
|
|
## References
|
|
|
|
- [Azure Instance Metadata service](https://docs.microsoft.com/en-us/azure/virtual-machines/windows/instance-metadata-service)
|
|
- [AAD Pod Identity](https://github.com/Azure/aad-pod-identity#demo)
|