Property
Languagehcl
Severitylow
CWECWE-778: Insufficient Logging
OWASPA10:2017 - Insufficient Logging & Monitoring
Confidence LevelLow
Impact LevelLow
Likelihood LevelLow

Description#

The EKS cluster configuration does not enable control plane logging for key components like the Kubernetes API server and audit logs. Without these logs, important actions and access events within the cluster may go unmonitored.

Impact#

If control plane logging is disabled, suspicious activity or security incidents in your EKS cluster may go undetected, making it harder to investigate breaches or unauthorized access. This lack of visibility can allow attackers to exploit the cluster without being noticed, increasing the risk to your infrastructure and data.