Property
Languagehcl
Severitylow
CWECWE-284: Improper Access Control
OWASPA05:2017 - Broken Access Control
Confidence LevelLow
Impact LevelLow
Likelihood LevelLow

Description#

The Google Kubernetes Engine (GKE) cluster configuration is missing VPC Flow Logs and intranode visibility. Without these settings, network traffic within and between nodes is not captured for monitoring or auditing.

Impact#

If exploited, this lack of visibility can let attackers move laterally or access sensitive data within the cluster without detection. It makes it harder to investigate incidents, detect suspicious activity, and comply with security policies.