Skip to main content

Master authorized networks are not configured

SeverityExploitabilityProvidersCategories
HIGHMEDIUMGoogle Cloud ProviderNETWORK

Description

Authorized networks restrict the origins from where the control planes of Google Kubernetes Engines (GKE) clusters can be accessed.

Impact

Potential data exposureVisible in logsUser interaction requiredPrivileges required
TrueFalseFalseFalse

Control planes can be accessed from anywhere, risking Distributed Denial-of-Service (DDoS). It may also be a risk of data exposure, if bruteforce attack is conducted.

Remediation guidelines

Enable master authorized networks, then configure the IP addresses allowed to access the GKE cluster's control plane.

References

How can I help you ?