# Improper Access Control (CWE-284) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. **Stack:** Kubernetes - Prevalence: 高 频繁被利用 - Impact: 高 3 条严重级别为高的规则 - Prevention: 已记录 4 个修复示例 **OWASP:** Broken Access Control (A01:2021-Broken Access Control) - #1 ## Description Access control involves determining which subjects can access which objects. When access control is implemented incorrectly, it can lead to unauthorized access to sensitive data or functionality. ## Prevention 基于 1 条 Shoulder 检测规则的 Improper Access Control 预防策略。 ### Kubernetes Define NetworkPolicy resources to restrict pod-to-pod traffic and enforce network segmentation ## Warning Signs - [MEDIUM] Workload has no NetworkPolicy for network segmentation - [MEDIUM] Kubernetes deployments without associated NetworkPolicy resources ## Consequences - 读取应用程序数据 - 修改应用程序数据 - 执行未授权代码 - 获取权限 ## Mitigations - 对所有资源实施适当的访问控制检查 - 采用最小权限原则 - 在服务器端而不仅是 UI 层强制执行访问控制 ## Detection - Total rules: 4 - Languages: go, javascript, typescript, kubernetes, yaml, python ## Rules by Language ### Kubernetes (1 rules) - **Missing Network Policy** [MEDIUM]: Detects Kubernetes deployments without associated NetworkPolicy resources. - Remediation: Define a NetworkPolicy to control pod network access. ```yaml kind: NetworkPolicy spec: podSelector: {} policyTypes: [Ingress] ``` Learn more: https://shoulder.dev/learn/kubernetes/cwe-284/missing-network-policy ### Yaml (1 rules) - **Missing Network Policy** [MEDIUM]: Detects Kubernetes deployments without associated NetworkPolicy resources. - Remediation: Define a NetworkPolicy to control pod network access. ```yaml kind: NetworkPolicy spec: podSelector: {} policyTypes: [Ingress] ``` Learn more: https://shoulder.dev/learn/kubernetes/cwe-284/missing-network-policy