Exposed Run Inside Container
An attacker could run arbitrary commands on a container via the kubelet’s /run endpoint. This endpoint is exposed as part of the kubelet’s debug handlers.
Recommended Actions
Disable --enable-debugging-handlers kubelet flag.
Links