Skip to main content

Persistent Volumes are Bound to Unauthorized Workloads

CCC.K8S.TH11

Misconfigured persistent-volume claims, storage classes, or workload authorization may allow a volume to be mounted outside its intended ownership boundary. Data stored on the volume can then be read, modified, or deleted through the unauthorized workload, directly reducing its confidentiality, integrity, and availability.

Related Capabilities

IDTitleDescription
CCC.K8S.CP13Kubernetes Storage ProvisioningThe service can dynamically provision ephemeral and persistent workload storage through Kubernetes container storage interface integrations.

Related Controls

IDTitleDescription
CCC.K8S.CN10Restrict Persistent Volume AccessConfine persistent storage provisioning and mounts to their approved namespace, workload, access mode, and ownership boundary.

External Mappings

FrameworkIDRelationshipRemarks
CWECWE-862relates-toMissing Authorization
MITRE-ATT&CKT1613relates-toContainer and Resource Discovery