Skip to main content

Untrusted Container Images are Deployed

CCC.K8S.TH04

Container images whose provenance, integrity, or vulnerability status is not verified may contain unsupported software, altered components, or embedded credentials and be admitted to the cluster. The image is then executed within the workload environment and can expose secrets, alter application data, or disrupt connected services.

Related Capabilities

IDTitleDescription
CCC.K8S.CP04OCI Container Image ExecutionThe service always accepts OCI-compatible image references and executes their containerized workloads through a Kubernetes-compatible runtime.
CCC.K8S.CP05Container Registry IntegrationThe service can authenticate to private or public OCI-compatible registries and retrieve workload images with user-configured identities and credentials.

Related Controls

IDTitleDescription
CCC.K8S.CN04Admit Only Trusted Container ImagesPrevent unapproved, mutable, unverifiable, or critically vulnerable container images from entering the workload environment.

External Mappings

FrameworkIDRelationshipRemarks
CWECWE-494relates-toDownload of Code Without Integrity Check
MITRE-ATT&CKT1195.002relates-toSupply Chain Compromise - Compromise Software Supply Chain
MITRE-ATT&CKT1525relates-toImplant Internal Image
MITRE-ATT&CKT1610relates-toDeploy Container