Best practices

Etcd directory ownership is not set to etcd:etcd

Platform(s)
  • Non-platform specific

Compliance Frameworks

CCPA, CPRA, iso_27001_2022, iso_27002_2022, K8s CIS, Mitre ATT&CK, NIST 800-171, NIST 800-190, NIST 800-53, PDPA, STIG K8s, UK Cyber Essentials

Description

It was found that the etcd directory file's owner is not set to etcd:etcd. Setting the file's owner to a low privileged user allows the modification of the file by this user and expose the configuration file to unwanted modification.