Haven't seen this mentioned on here yet: Complete remote compromise of the Kubernetes backend via cluster management API - unauthenticated in the default configuration, authenticated when the operator secured the discovery API: CVE-2018-1002105

