Kubetier
  1. Create a CRD that registers a conversion webhook pointing at an attacker-controlled server.

  2. Reads or writes that require version conversion are routed through the webhook, which can read and rewrite those objects in flight.

  3. The API server requires a CA bundle and TLS, so this needs a serving certificate the API server will accept.

CVE-2022-3162↗
K8s docs ↗