Skip to content

Kubernetes API Unauthenticated Access

kubernetes-api-unauthenticated is a critical severity check in the devops category, written in yaml. Its source is templates/devops/kubernetes/kubernetes-api-unauthenticated-default.yaml in cert-x-gen-templates.

Detects unauthenticated access to Kubernetes API server. Unauthenticated access to the Kubernetes API can allow attackers to enumerate cluster resources, deploy malicious pods, access secrets, and potentially gain full control of the Kubernetes cluster.

Field Value
Id kubernetes-api-unauthenticated
Severity critical
Language yaml
Category devops
Author CERT-X-GEN
Template version 1.0.0
Confidence 90
CVSS 9.8
Weakness CWE-306, CWE-284
Tags kubernetes, api, unauthenticated, container, orchestration, cve
Target kind not recorded
Oracle not recorded

The file declares extractors, http, network, remediation as well. Those are not tabled above; read the source for what they carry.

Declared in the header. cxg parses @references and then discards it, and nothing at scan time reads it, so this is the only place the links a template cites are surfaced.

To see what the copy on your machine says about itself, and to confirm it is installed at all:

Terminal window
cxg template info kubernetes-api-unauthenticated

The id it prints is the one to pass anywhere a template is selected. See cxg template for the rest of the subcommand, Scan a target for running a scan, and A match is not a finding for how to read what comes back.