logo

Database

Azure Not Using Latest Version

Description

Detects Azure Kubernetes Service (AKS) clusters that are not running on the latest available stable version. Running outdated Kubernetes versions can expose clusters to known vulnerabilities and security risks due to missing security patches and updates.

Weakness:

446 - Insecure service configuration - Azure

Category: Functionality Abuse

Detection Strategy

    Checks the AKS cluster's upgrade profile to determine if newer versions are available for upgrade

    Reports a vulnerability if there are non-preview version upgrades available for the control plane

    Only considers stable (non-preview) versions when determining if an upgrade is available

Severity v4.0

1.7

Low

Method ID

CSPM-AT4VN

Technique

CSPM

Target

AZURE

Technology

AKS

CWE ID(s)

CWE-1188