Rule ID
SV-242459r961863_rule
Version
V2R6
CCIs
The Kubernetes etcd key-value store provides a way to store data to the Control Plane. If these files can be changed, data to API object and Control Plane would be compromised.
Review the permissions of the Kubernetes etcd by using the command: ls -AR /var/lib/etcd/* If any of the files have permissions more permissive than "644", this is a finding.
Change the permissions of the manifest files to "644" by executing the command: chmod -R 644 /var/lib/etcd/*