Skip to main content

Unsupported Cluster Components Remain in Use

CCC.K8S.TH09

Control-plane, worker, runtime, or extension versions outside their supported lifecycles may retain known vulnerabilities and compatibility defects. Exposed components can then be exploited or may fail during service changes, leading to data exposure, loss of cluster-state integrity, or workload interruption.

Related Capabilities

IDTitleDescription
CCC.K8S.CP02Managed Worker PoolsThe service can organize worker nodes into managed pools that provide Kubernetes with compute capacity for scheduling and running containerized workloads.
CCC.K8S.CP03Abstracted Worker InfrastructureThe service may be configured to abstract worker infrastructure so that provisioning, scaling, patching, and replacement occur without exposing individual nodes to the user.
CCC.K8S.CP15Cluster Version ManagementThe service may be configured with upgrade channels and maintenance settings that keep control-plane and worker components within provider-defined compatibility and support periods.

Related Controls

IDTitleDescription
CCC.K8S.CN09Maintain Supported Cluster ComponentsKeep control-plane, worker, runtime, and extension components within supported and vulnerability-managed release lifecycles.
CCC.K8S.CN18Protect Worker Node IntegrityPrevent untrusted or altered worker-node software from operating beneath Kubernetes workloads.

External Mappings

FrameworkIDRelationshipRemarks
CWECWE-1104relates-toUse of Unmaintained Third Party Components
MITRE-ATT&CKT1190relates-toExploit Public-Facing Application
MITRE-ATT&CKT1611relates-toEscape to Host