Skip to main content

GKE Control Plane should not be publicly accessible

SeverityExploitabilityProvidersCategories
HIGHMEDIUMGoogle Cloud ProviderNETWORK

Description

GKE (Google Kubernetes Engine) Control Plane manages various processes run by GKE cluster nodes. It should have restricted access, but is publicly accessible by default.

Impact

Potential data exposureVisible in logsUser interaction requiredPrivileges required
TrueFalseFalseFalse

Potential Distributed Denial-of-Service (DDoS) and bruteforce on credentials.

Remediation guidelines

Set nodes to private and manage master authorized network.

References

How can I help you ?