Best practices

Kubernetes Controller Manager –profiling argument is not set to false

Platform(s)
  • Non-platform specific

Compliance Frameworks
  • CCPA
  • ,
  • CPRA
  • ,
  • iso_27001_2022
  • ,
  • iso_27002_2022
  • ,
  • K8s CIS
  • ,
  • Mitre ATT&CK
  • ,
  • NIST 800-171
  • ,
  • NIST 800-190
  • ,
  • NIST 800-53
  • ,
  • PDPA
  • ,
  • STIG K8s
  • ,
  • UK Cyber Essentials

Description

It was found that the argument --profiling in the Controller Manager configuration file is not set to False. Profiling is used to identify performance bottlenecks. When enabled, the feature can be exploited by a malicious actor to uncover system and program details.