CNTR-K8-000430 - Kubernetes Kubectl cp command must give expected access and results.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

One of the tools heavily used to interact with containers in the Kubernetes cluster is kubectl. The command is the tool System Administrators used to create, modify, and delete resources. One of the capabilities of the tool is to copy files to and from running containers (i.e., kubectl cp). The command uses the 'tar' command of the container to copy files from the container to the host executing the 'kubectl cp' command. If the 'tar' command on the container has been replaced by a malicious user, the command can copy files anywhere on the host machine. This flaw has been fixed in later versions of the tool. It is recommended to use kubectl versions newer than 1.12.9.

Solution

Upgrade the Control Plane and Worker nodes to the latest version of kubectl.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Kubernetes_V1R10_STIG.zip

Item Details

References: CAT|II, CCI|CCI-000213, Rule-ID|SV-242396r879530_rule, STIG-ID|CNTR-K8-000430, Vuln-ID|V-242396

Plugin: Unix

Control ID: 08eed6d757a4246440645a3e991bd3e157fdd69307df72c2069ed065ff89100f