Skip to main content

Cluster Infrastructure Identities Grant Excessive Cloud Access

CCC.K8S.TH17

Cloud identities used by control-plane, worker-node, or supporting components may be shared or granted permissions beyond their platform responsibilities. A component using such an identity can access or modify cloud resources outside its intended boundary. Protected cloud data may be disclosed, cloud resource integrity may be lost, and services required by the cluster may be disrupted.

Related Capabilities

IDTitleDescription
CCC.K8S.CP02Managed Worker PoolsThe service can organize worker nodes into managed pools that provide Kubernetes with compute capacity for scheduling and running containerized workloads.
CCC.K8S.CP21Cluster Infrastructure IdentityThe service may be configured with distinct cloud identities for control-plane, worker-node, and supporting components so their access to cloud resources can be independently authorized.

Related Controls

IDTitleDescription
CCC.K8S.CN17Restrict Cluster Infrastructure IdentitiesLimit cloud access by cluster infrastructure to the permissions and resources required for each platform responsibility.

External Mappings

FrameworkIDRelationshipRemarks
CWECWE-269relates-toImproper Privilege Management
MITRE-ATT&CKT1078.004relates-toValid Accounts - Cloud Accounts