Skip to content

H3-2021-0006

Unauthenticated Kubernetes API Server Access

Category SECURITY_MISCONFIGURATION
Base Score 7.5

Description

The Kubernetes API Server port is accessible to anonymous (unauthenticated) users.

Impact

An attacker could make requests to the API server to access sensitive information such as running pods and secrets. Depending on the level of access, attackers may be able to fully compromise the cluster.

References