Skip to main content

GKE metadata is not concealed

SeverityExploitabilityProvidersCategories
HIGHLOWGoogle Cloud ProviderSECRET

Description

GKE instance metadata may contain secrets information. Those should be protected and isolated from the workloads running on the cluster.

Impact

Potential data exposureVisible in logsUser interaction requiredPrivileges required
TrueFalseFalseFalse

Secret metadata information may leak.

Remediation guidelines

Either:

  • Set metadata to SECURE
  • Set metadata to GKE_METADATA_SERVER, if workload identity is enabled.

References

How can I help you ?