Skip to main content

Workload Endpoints are Exposed Unintentionally

CCC.K8S.TH10

Services, load balancers, ingress resources, or gateways configured with an unintended external scope may make workload endpoints reachable from untrusted networks. Exposed services can then disclose workload data, accept unauthorized changes, or consume capacity needed by legitimate users.

Related Capabilities

IDTitleDescription
CCC.K8S.CP08Workload Traffic RoutingThe service can expose and route internal or external traffic to Kubernetes workloads through services, load balancers, ingress controllers, and gateway components.

Related Controls

IDTitleDescription
CCC.K8S.CN06Enforce Default-Deny Workload Network PoliciesConfine workload communication to flows permitted by explicit, least-privilege network policies, with all other traffic denied by default.
CCC.K8S.CN14Preserve Kubernetes Audit and Monitoring RecordsMaintain complete, externally retained, access-controlled, and monitored records of security-relevant Kubernetes activity and health signals.

External Mappings

FrameworkIDRelationshipRemarks
CWECWE-284relates-toImproper Access Control
MITRE-ATT&CKT1046relates-toNetwork Service Discovery
MITRE-ATT&CKT1190relates-toExploit Public-Facing Application