Property
Languagehcl
Severitylow
CWECWE-284: Improper Access Control
OWASPA05:2017 - Broken Access Control
Confidence LevelLow
Impact LevelLow
Likelihood LevelLow

Description#

The GKE cluster configuration enables basic authentication using a static username and password, which is insecure and should be disabled. This approach exposes the cluster to unauthorized access if credentials are leaked or guessed.

Impact#

If exploited, attackers could gain administrative access to your Kubernetes cluster, allowing them to steal data, deploy malicious workloads, or disrupt services. This could lead to data breaches, service outages, and further compromise of your cloud environment.