We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
kro (Kube Resource Orchestrator) 0.1.0 before 0.2.1 allows users (with permission to create or modify ResourceGraphDefinition resources) to supply arbitrary container images. This can lead to a confused-deputy scenario where kro's controllers deploy and run attacker-controlled images, resulting in unauthenticated remote code execution on cluster nodes.
Reserved 2025-05-23 | Published 2025-06-04 | Updated 2025-06-04 | Assigner mitreCWE-441: Unintended Proxy or Intermediary ('Confused Deputy')
github.com/kro-run/kro/compare/v0.2.1...v0.2.2
orca.security/.../blog/kubernetes-crd-abstraction-risks-kro/
Support options