Skip to main content

Orchestration / K8S

CCC Managed Kubernetes Container Orchestration Threats

Version: DEV

IDTitleDescriptionExternal MappingsCapability MappingsControl Mappings
CCC.K8S.TH01Kubernetes API is Exposed to Untrusted NetworksAn API endpoint without network restrictions may be reached from untrusted networks. Cluster resources and configuration can then be enumerated or modified through exposed administrative interfaces. Cluster data may be disclosed, configuration integrity may be lost, and workloads may be disrupted.211
CCC.K8S.TH02Workload Identity Grants Excessive Cloud AccessA Kubernetes service account bound to an overprivileged cloud identity may give its workloads permissions beyond their operational needs. Cloud resources can then be accessed or modified outside the workload's intended boundary, exposing protected data and allowing unauthorized changes to cloud state.213
CCC.K8S.TH03Long-Lived Credentials are Exposed to WorkloadsLong-lived cloud credentials stored in workload configuration, container images, environment variables, or mounted files may be read by a compromised workload or unauthorized user. The credentials can then be used independently of the workload lifecycle. Protected data may be disclosed and resources accessible through those credentials may be modified outside the cluster's authorization controls.212
CCC.K8S.TH04Untrusted Container Images are DeployedContainer images whose provenance, integrity, or vulnerability status is not verified may contain unsupported software, altered components, or embedded credentials and be admitted to the cluster. The image is then executed within the workload environment and can expose secrets, alter application data, or disrupt connected services.211
CCC.K8S.TH05Privileged Workloads Escape IsolationWorkloads granted privileged execution, host namespaces, host paths, or unrestricted Linux capabilities may bypass container isolation controls. Processes can then read node data, alter host state, or disrupt neighboring workloads, defeating the confidentiality, integrity, and availability boundaries of the shared worker infrastructure.212
CCC.K8S.TH06Workload Network Segmentation is Not EnforcedAbsent or ineffective ingress and egress policies may allow traffic to flow between namespaces, workloads, and external systems without an explicit authorization boundary. Network services can then be discovered or reached from unintended sources, exposing data flows, permitting unauthorized interaction, and increasing the risk of workload disruption.211
CCC.K8S.TH07Secrets are Exposed to Unauthorized WorkloadsMisconfigured secret access, namespace boundaries, or workload mounts may expose sensitive values to workloads or users that do not require them. Credentials, keys, or certificates can then be read from Kubernetes or external secret interfaces, exposing the secrets and enabling unauthorized changes to the resources they protect.212
CCC.K8S.TH08Cluster Extensions Execute Untrusted CodeAn operator, controller, admission webhook, or managed extension installed without verified provenance and constrained permissions may execute untrusted code with cluster-level access. The extension can intercept sensitive data, rewrite cluster state, or interrupt workloads across its granted scope.211
CCC.K8S.TH09Unsupported Cluster Components Remain in UseControl-plane, worker, runtime, or extension versions outside their supported lifecycles may retain known vulnerabilities and compatibility defects. Exposed components can then be exploited or may fail during service changes, leading to data exposure, loss of cluster-state integrity, or workload interruption.212
CCC.K8S.TH10Workload Endpoints are Exposed UnintentionallyServices, load balancers, ingress resources, or gateways configured with an unintended external scope may make workload endpoints reachable from untrusted networks. Exposed services can then disclose workload data, accept unauthorized changes, or consume capacity needed by legitimate users.212
CCC.K8S.TH11Persistent Volumes are Bound to Unauthorized WorkloadsMisconfigured persistent-volume claims, storage classes, or workload authorization may allow a volume to be mounted outside its intended ownership boundary. Data stored on the volume can then be read, modified, or deleted through the unauthorized workload, directly reducing its confidentiality, integrity, and availability.211
CCC.K8S.TH12Admission Controls are BypassedAdmission policies that omit resources, namespaces, or API paths may allow a Kubernetes request to be accepted without the intended validation or mutation. Workloads and configuration that violate security requirements can then be persisted, weakening cluster-policy integrity and exposing workloads to unauthorized access or disruption.212
CCC.K8S.TH13Controllers Reconcile Unauthorized Cluster StateA controller or scheduled workload granted excessive scope may repeatedly create or restore unauthorized resources and configuration through its reconciliation loop. Manual remediation can then be overwritten, restoring unsafe cluster state that exposes workload data or interferes with service availability.212
CCC.K8S.TH14Node Administrative Interfaces Expose Cluster CredentialsNode administrative interfaces reachable without sufficient authentication or network restriction may expose node metadata, workload credentials, logs, or execution functions. The node can then be queried or controlled outside the intended management path, allowing credential disclosure, unauthorized host changes, or disruption of scheduled workloads.211
CCC.K8S.TH15Kubernetes Audit Records are Incomplete or UnavailableAudit policies, log categories, collection agents, export destinations, or retention settings that omit security-relevant activity may leave required Kubernetes records incomplete or unavailable. Cluster access and configuration changes can then occur without a reliable investigative trail, delaying detection and weakening the integrity and availability of security monitoring and incident response.211
CCC.K8S.TH16Unmanaged Credentials Bypass Cluster Identity ControlsLocally managed accounts, static administrative credentials, or legacy authentication methods may remain valid after the associated identity should lose access. Requests authenticated by these mechanisms can bypass centrally managed identity lifecycle and revocation controls. Cluster data may be disclosed, cluster state may be changed, and workloads may be disrupted through unauthorized administrative access.211
CCC.K8S.TH17Cluster Infrastructure Identities Grant Excessive Cloud AccessCloud identities used by control-plane, worker-node, or supporting components may be shared or granted permissions beyond their platform responsibilities. A component using such an identity can access or modify cloud resources outside its intended boundary. Protected cloud data may be disclosed, cloud resource integrity may be lost, and services required by the cluster may be disrupted.211
CCC.K8S.TH18Worker Node Integrity Is Not VerifiedWorker nodes created from untrusted or altered images, or started without boot integrity verification, may execute modified software beneath the container runtime. Modified node components can observe workload data and credentials or alter workload execution. Workload confidentiality and integrity may be lost, and node or cluster availability may be reduced.211

Imports

IDRemarks
CCC.Core.TH01Access is Granted to Unauthorized Users
CCC.Core.TH02Data is Intercepted in Transit
CCC.Core.TH03Deployment Region Network is Untrusted
CCC.Core.TH07Logs are Tampered With or Deleted
CCC.Core.TH09Runtime Logs are Read by Unauthorized Entities
CCC.Core.TH10State-change Events are Read by Unauthorized Entities
CCC.Core.TH11Publications are Incorrectly Triggered
CCC.Core.TH12Resource Constraints are Exhausted
CCC.Core.TH13Resource Tags are Manipulated
CCC.Core.TH15Automated Enumeration and Reconnaissance by Non-human Entities
CCC.Core.TH16Publications are Disabled
CCC.Core.TH17Responses are Generated for Unauthorized Requests
CCC.Core.TH18Encryption Key is Misused