C 0048
AllControls, WorkloadScan, MITRE, ClusterScan, security
Severity
High
Description of the the issue
Mounting host directory to the container can be used by attackers to get access to the underlying host. This control identifies all the pods using hostPath mount.
Related resources
CronJob, DaemonSet, Deployment, Job, Pod, ReplicaSet, StatefulSet
What does this control test
Mounting host directory to the container can be used by attackers to get access to the underlying host. This control identifies all the pods using hostPath mount.
Remediation
Remove hostPath mounts unless they are absolutely necessary and use exception mechanism to remove notifications.