logo

Database

Azure Api Server Public Access

Description

Detects Azure Kubernetes Service (AKS) clusters that don't have API server access profile configurations defined, which could allow unrestricted public access to the Kubernetes control plane. Unrestricted API server access increases the attack surface and risk of unauthorized cluster management.

Weakness:

446 - Insecure service configuration - Azure

Category: Functionality Abuse

Detection Strategy

    Scans all AKS clusters in the Azure subscription

    Reports a vulnerability when an AKS cluster has no 'api_server_access_profile' configuration defined

    Each vulnerable cluster is reported with its resource ID and configuration state