configmap-executable-code
Scripts stored in a ConfigMap and executed by a pod turn ConfigMap write access into code execution inside the container, bypassing image scanning, image signing and any review of what actually runs.
!has(object.data) || !object.data.exists(
k,
v,
k.lowerAscii().matches(".*\\.(sh|bash|py|lua|js|ts|rb|pl|php|groovy|tmpl)$") ||
v.matches("(?s).*#!/\\S+") ||
v.matches("(?i).*\\b(function|import|require|process|exec)\\b.*")
)
Do not store executable code or scripts in ConfigMaps that applications run.
Move scripts, shebang files and other executable content into the container image or a signed artifact, keeping only inert configuration values in the ConfigMap. Field: data.
apiVersion: admissionregistration.k8s.io/v1
kind: ValidatingAdmissionPolicy
metadata:
name: configmap-executable-code
annotations:
kubeapt.io/uuid: "2d9872e4-6538-497b-b9f1-64479e562fcd"
security.kubeapt.io/displayName: "Stores Executable Code or Scripts"
security.kubeapt.io/description: "Scripts stored in a ConfigMap and executed by a pod turn ConfigMap write access into code execution inside the container, bypassing image scanning, image signing and any review of what actually runs."
security.kubeapt.io/resource: "ConfigMaps"
security.kubeapt.io/severity: "Moderate"
security.kubeapt.io/remediation: "Move scripts, shebang files and other executable content into the container image or a signed artifact, keeping only inert configuration values in the ConfigMap. Field: data."
security.kubeapt.io/product: "Kubernetes"
spec:
failurePolicy: Fail
matchConstraints:
resourceRules:
- apiGroups:
- ''
apiVersions:
- v1
operations:
- CREATE
- UPDATE
resources:
- configmaps
validations:
- expression: |
!has(object.data) || !object.data.exists(
k,
v,
k.lowerAscii().matches(".*\\.(sh|bash|py|lua|js|ts|rb|pl|php|groovy|tmpl)$") ||
v.matches("(?s).*#!/\\S+") ||
v.matches("(?i).*\\b(function|import|require|process|exec)\\b.*")
)
message: |
Do not store executable code or scripts in ConfigMaps that applications run.Save it as configmap-executable-code.yaml — the commands below assume that name.
Check a workload against this one policy, before anything is installed on a cluster.
$ kubeapt validate -p ./configmap-executable-code.yaml -r ./workload.yamlOr without the file, from the published policy set — -r takes a directory too:
$ kubeapt policies download && kubeapt validate --policy-name configmap-executable-code -r ./manifestsOr against every namespace in the cluster your kubeconfig points at:
$ kubeapt validate --policy-name configmap-executable-code -A