{
  "schemaVersion": "catalog-shared-check-receipt-v1",
  "subject": {
    "id": "hashicorp-consul-2-0-0-secure-mesh-existing-secrets",
    "chart": "hashicorp/consul",
    "version": "2.0.0",
    "base": "secure-mesh-existing-secrets",
    "renderPath": "recipes/hashicorp/consul/2.0.0/revisions/secure-mesh-existing-secrets/r001/rendered/release-objects.yaml",
    "renderFileSHA256": "sha256:0acc8c339c2965446b754c3a9c948c4f154ca6e47b074ddc3b8d315e2cb7c468"
  },
  "catalogReview": {
    "path": "recipes/hashicorp/consul/2.0.0/revisions/secure-mesh-existing-secrets/r001/receipts/scan-receipt.yaml",
    "note": "Separate chart-specific Catalog review; not a cub check result."
  },
  "scannerResult": {
    "schema_version": "risk-scan-findings-v1",
    "surface": "cub-scan",
    "finding_count": 22,
    "findings": [
      {
        "id": "CCVE-2025-3740",
        "name": "Deployment explicitly sets replicas to 1",
        "category": "CONFIG",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "info",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "Deployment",
          "name": "consul-consul-connect-injector",
          "namespace": "consul"
        },
        "message": "Deployment has replicas: 1; no high availability",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Set replicas to at least 2 for services requiring availability",
            "Use HPA with minReplicas >= 2 for auto-scaling workloads",
            "Single replica is acceptable for batch jobs or development"
          ],
          "commands": [
            "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.replicas}'"
          ]
        },
        "evidence_source": "native",
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Set replicas to at least 2 for services requiring availability",
          "command": "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.replicas}'",
          "doc_ref": "cub-scan --explain CCVE-2025-3740"
        }
      },
      {
        "id": "CCVE-2025-3740",
        "name": "Deployment explicitly sets replicas to 1",
        "category": "CONFIG",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "info",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "Deployment",
          "name": "consul-consul-ingress-gateway",
          "namespace": "consul"
        },
        "message": "Deployment has replicas: 1; no high availability",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Set replicas to at least 2 for services requiring availability",
            "Use HPA with minReplicas >= 2 for auto-scaling workloads",
            "Single replica is acceptable for batch jobs or development"
          ],
          "commands": [
            "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.replicas}'"
          ]
        },
        "evidence_source": "native",
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Set replicas to at least 2 for services requiring availability",
          "command": "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.replicas}'",
          "doc_ref": "cub-scan --explain CCVE-2025-3740"
        }
      },
      {
        "id": "CCVE-2025-3740",
        "name": "Deployment explicitly sets replicas to 1",
        "category": "CONFIG",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "info",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "Deployment",
          "name": "consul-consul-mesh-gateway",
          "namespace": "consul"
        },
        "message": "Deployment has replicas: 1; no high availability",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Set replicas to at least 2 for services requiring availability",
            "Use HPA with minReplicas >= 2 for auto-scaling workloads",
            "Single replica is acceptable for batch jobs or development"
          ],
          "commands": [
            "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.replicas}'"
          ]
        },
        "evidence_source": "native",
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Set replicas to at least 2 for services requiring availability",
          "command": "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.replicas}'",
          "doc_ref": "cub-scan --explain CCVE-2025-3740"
        }
      },
      {
        "id": "CCVE-2025-3740",
        "name": "Deployment explicitly sets replicas to 1",
        "category": "CONFIG",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "info",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "Deployment",
          "name": "consul-consul-terminating-gateway",
          "namespace": "consul"
        },
        "message": "Deployment has replicas: 1; no high availability",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Set replicas to at least 2 for services requiring availability",
            "Use HPA with minReplicas >= 2 for auto-scaling workloads",
            "Single replica is acceptable for batch jobs or development"
          ],
          "commands": [
            "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.replicas}'"
          ]
        },
        "evidence_source": "native",
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Set replicas to at least 2 for services requiring availability",
          "command": "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.replicas}'",
          "doc_ref": "cub-scan --explain CCVE-2025-3740"
        }
      },
      {
        "id": "CCVE-2025-3740",
        "name": "Deployment explicitly sets replicas to 1",
        "category": "CONFIG",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "info",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "Deployment",
          "name": "consul-consul-webhook-cert-manager",
          "namespace": "consul"
        },
        "message": "Deployment has replicas: 1; no high availability",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Set replicas to at least 2 for services requiring availability",
            "Use HPA with minReplicas >= 2 for auto-scaling workloads",
            "Single replica is acceptable for batch jobs or development"
          ],
          "commands": [
            "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.replicas}'"
          ]
        },
        "evidence_source": "native",
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Set replicas to at least 2 for services requiring availability",
          "command": "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.replicas}'",
          "doc_ref": "cub-scan --explain CCVE-2025-3740"
        }
      },
      {
        "id": "CCVE-2025-3745",
        "name": "emptyDir volume has no sizeLimit",
        "category": "CONFIG",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "info",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "Deployment",
          "name": "consul-consul-ingress-gateway",
          "namespace": "consul"
        },
        "message": "Volume consul-service uses emptyDir without sizeLimit; may exhaust node disk",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Set sizeLimit on all emptyDir volumes",
            "Size the limit based on expected usage with headroom",
            "{'Consider using memory-backed emptyDir (medium': 'Memory) for small caches'}"
          ],
          "commands": [
            "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.template.spec.volumes}'"
          ]
        },
        "evidence_source": "native",
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Set sizeLimit on all emptyDir volumes",
          "command": "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.template.spec.volumes}'",
          "doc_ref": "cub-scan --explain CCVE-2025-3745"
        }
      },
      {
        "id": "CCVE-2025-3745",
        "name": "emptyDir volume has no sizeLimit",
        "category": "CONFIG",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "info",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "Deployment",
          "name": "consul-consul-mesh-gateway",
          "namespace": "consul"
        },
        "message": "Volume consul-service uses emptyDir without sizeLimit; may exhaust node disk",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Set sizeLimit on all emptyDir volumes",
            "Size the limit based on expected usage with headroom",
            "{'Consider using memory-backed emptyDir (medium': 'Memory) for small caches'}"
          ],
          "commands": [
            "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.template.spec.volumes}'"
          ]
        },
        "evidence_source": "native",
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Set sizeLimit on all emptyDir volumes",
          "command": "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.template.spec.volumes}'",
          "doc_ref": "cub-scan --explain CCVE-2025-3745"
        }
      },
      {
        "id": "CCVE-2025-3745",
        "name": "emptyDir volume has no sizeLimit",
        "category": "CONFIG",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "info",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "Deployment",
          "name": "consul-consul-terminating-gateway",
          "namespace": "consul"
        },
        "message": "Volume consul-service uses emptyDir without sizeLimit; may exhaust node disk",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Set sizeLimit on all emptyDir volumes",
            "Size the limit based on expected usage with headroom",
            "{'Consider using memory-backed emptyDir (medium': 'Memory) for small caches'}"
          ],
          "commands": [
            "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.template.spec.volumes}'"
          ]
        },
        "evidence_source": "native",
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Set sizeLimit on all emptyDir volumes",
          "command": "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.template.spec.volumes}'",
          "doc_ref": "cub-scan --explain CCVE-2025-3745"
        }
      },
      {
        "id": "CCVE-2025-3746",
        "name": "Deployment does not disable automountServiceAccountToken",
        "category": "SECURITY",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "warning",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "Deployment",
          "name": "consul-consul-connect-injector",
          "namespace": "consul"
        },
        "message": "Deployment does not set automountServiceAccountToken: false; pods get unnecessary API credentials",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Set automountServiceAccountToken to false in the pod spec",
            "Only enable it for pods that genuinely need Kubernetes API access",
            "Use dedicated service accounts with minimal RBAC for pods that need API access"
          ],
          "commands": [
            "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.template.spec.automountServiceAccountToken}'"
          ]
        },
        "evidence_source": "native",
        "control_ids": [
          "CTRL-RBAC-0002"
        ],
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Set automountServiceAccountToken to false in the pod spec",
          "command": "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.template.spec.automountServiceAccountToken}'",
          "doc_ref": "cub-scan --explain CCVE-2025-3746"
        }
      },
      {
        "id": "CCVE-2025-3746",
        "name": "Deployment does not disable automountServiceAccountToken",
        "category": "SECURITY",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "warning",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "Deployment",
          "name": "consul-consul-ingress-gateway",
          "namespace": "consul"
        },
        "message": "Deployment does not set automountServiceAccountToken: false; pods get unnecessary API credentials",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Set automountServiceAccountToken to false in the pod spec",
            "Only enable it for pods that genuinely need Kubernetes API access",
            "Use dedicated service accounts with minimal RBAC for pods that need API access"
          ],
          "commands": [
            "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.template.spec.automountServiceAccountToken}'"
          ]
        },
        "evidence_source": "native",
        "control_ids": [
          "CTRL-RBAC-0002"
        ],
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Set automountServiceAccountToken to false in the pod spec",
          "command": "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.template.spec.automountServiceAccountToken}'",
          "doc_ref": "cub-scan --explain CCVE-2025-3746"
        }
      },
      {
        "id": "CCVE-2025-3746",
        "name": "Deployment does not disable automountServiceAccountToken",
        "category": "SECURITY",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "warning",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "Deployment",
          "name": "consul-consul-mesh-gateway",
          "namespace": "consul"
        },
        "message": "Deployment does not set automountServiceAccountToken: false; pods get unnecessary API credentials",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Set automountServiceAccountToken to false in the pod spec",
            "Only enable it for pods that genuinely need Kubernetes API access",
            "Use dedicated service accounts with minimal RBAC for pods that need API access"
          ],
          "commands": [
            "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.template.spec.automountServiceAccountToken}'"
          ]
        },
        "evidence_source": "native",
        "control_ids": [
          "CTRL-RBAC-0002"
        ],
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Set automountServiceAccountToken to false in the pod spec",
          "command": "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.template.spec.automountServiceAccountToken}'",
          "doc_ref": "cub-scan --explain CCVE-2025-3746"
        }
      },
      {
        "id": "CCVE-2025-3746",
        "name": "Deployment does not disable automountServiceAccountToken",
        "category": "SECURITY",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "warning",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "Deployment",
          "name": "consul-consul-terminating-gateway",
          "namespace": "consul"
        },
        "message": "Deployment does not set automountServiceAccountToken: false; pods get unnecessary API credentials",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Set automountServiceAccountToken to false in the pod spec",
            "Only enable it for pods that genuinely need Kubernetes API access",
            "Use dedicated service accounts with minimal RBAC for pods that need API access"
          ],
          "commands": [
            "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.template.spec.automountServiceAccountToken}'"
          ]
        },
        "evidence_source": "native",
        "control_ids": [
          "CTRL-RBAC-0002"
        ],
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Set automountServiceAccountToken to false in the pod spec",
          "command": "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.template.spec.automountServiceAccountToken}'",
          "doc_ref": "cub-scan --explain CCVE-2025-3746"
        }
      },
      {
        "id": "CCVE-2025-3746",
        "name": "Deployment does not disable automountServiceAccountToken",
        "category": "SECURITY",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "warning",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "Deployment",
          "name": "consul-consul-webhook-cert-manager",
          "namespace": "consul"
        },
        "message": "Deployment does not set automountServiceAccountToken: false; pods get unnecessary API credentials",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Set automountServiceAccountToken to false in the pod spec",
            "Only enable it for pods that genuinely need Kubernetes API access",
            "Use dedicated service accounts with minimal RBAC for pods that need API access"
          ],
          "commands": [
            "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.template.spec.automountServiceAccountToken}'"
          ]
        },
        "evidence_source": "native",
        "control_ids": [
          "CTRL-RBAC-0002"
        ],
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Set automountServiceAccountToken to false in the pod spec",
          "command": "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.template.spec.automountServiceAccountToken}'",
          "doc_ref": "cub-scan --explain CCVE-2025-3746"
        }
      },
      {
        "id": "CCVE-2025-3752",
        "name": "StatefulSet does not disable automountServiceAccountToken",
        "category": "SECURITY",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "warning",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "StatefulSet",
          "name": "consul-consul-server",
          "namespace": "consul"
        },
        "message": "StatefulSet does not set automountServiceAccountToken: false; pods get unnecessary API credentials",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Set automountServiceAccountToken to false in the pod spec",
            "Only enable it for pods that genuinely need Kubernetes API access",
            "Use dedicated service accounts with minimal RBAC for pods that need API access"
          ],
          "commands": [
            "kubectl get statefulset <name> -n <namespace> -o jsonpath='{.spec.template.spec.automountServiceAccountToken}'"
          ]
        },
        "evidence_source": "native",
        "control_ids": [
          "CTRL-RBAC-0002"
        ],
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Set automountServiceAccountToken to false in the pod spec",
          "command": "kubectl get statefulset <name> -n <namespace> -o jsonpath='{.spec.template.spec.automountServiceAccountToken}'",
          "doc_ref": "cub-scan --explain CCVE-2025-3752"
        }
      },
      {
        "id": "CCVE-2025-3765",
        "name": "Ingress has no TLS configuration",
        "category": "SECURITY",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "warning",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "Ingress",
          "name": "consul-consul-ui",
          "namespace": "consul"
        },
        "message": "Ingress has no TLS configuration; traffic is unencrypted",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Add spec.tls with the appropriate hosts and secretName",
            "Create a TLS Secret with the certificate and key",
            "Consider using cert-manager for automatic certificate management"
          ],
          "commands": [
            "kubectl get ingress <name> -n <namespace> -o jsonpath='{.spec.tls}'"
          ]
        },
        "evidence_source": "native",
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Add spec.tls with the appropriate hosts and secretName",
          "command": "kubectl get ingress <name> -n <namespace> -o jsonpath='{.spec.tls}'",
          "doc_ref": "cub-scan --explain CCVE-2025-3765"
        }
      },
      {
        "id": "CCVE-2025-3766",
        "name": "Ingress has no ingressClassName",
        "category": "CONFIG",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "warning",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "Ingress",
          "name": "consul-consul-ui",
          "namespace": "consul"
        },
        "message": "Ingress has no ingressClassName; may not be picked up by any controller",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Set spec.ingressClassName to the appropriate controller class",
            "Common values are nginx, traefik, alb"
          ],
          "commands": [
            "kubectl get ingressclass",
            "kubectl get ingress <name> -n <namespace> -o jsonpath='{.spec.ingressClassName}'"
          ]
        },
        "evidence_source": "native",
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Set spec.ingressClassName to the appropriate controller class",
          "command": "kubectl get ingressclass",
          "doc_ref": "cub-scan --explain CCVE-2025-3766"
        }
      },
      {
        "id": "CCVE-2025-4005",
        "name": "CCVE-2025-4005",
        "category": "CONFIGURATION",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "warning",
        "confidence": "unknown",
        "tool": "kubernetes",
        "resource": {
          "kind": "Deployment",
          "name": "consul-consul-connect-injector",
          "namespace": "consul"
        },
        "message": "Volume certs references Secret consul/consul-consul-connect-inject-webhook-cert which is not present in scanned documents",
        "remedy_type": "manual_only",
        "remedy_safety": "manual_only",
        "remediation": {
          "steps": [
            "Verify the ConfigMap or Secret name in the volume reference matches an existing resource",
            "Create the missing ConfigMap/Secret or correct the volume reference"
          ],
          "commands": [
            "kubectl get configmap -n <namespace>",
            "kubectl get secret -n <namespace>"
          ]
        },
        "evidence_source": "native",
        "action_type": "human-decision",
        "next_step": {
          "action": "update_config",
          "description": "Verify the ConfigMap or Secret name in the volume reference matches an existing resource",
          "command": "kubectl get configmap -n <namespace>",
          "doc_ref": "cub-scan --explain CCVE-2025-4005"
        }
      },
      {
        "id": "CCVE-2025-4005",
        "name": "CCVE-2025-4005",
        "category": "CONFIGURATION",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "warning",
        "confidence": "unknown",
        "tool": "kubernetes",
        "resource": {
          "kind": "Deployment",
          "name": "consul-consul-ingress-gateway",
          "namespace": "consul"
        },
        "message": "Volume consul-ca-cert references Secret consul/consul-ca-cert which is not present in scanned documents",
        "remedy_type": "manual_only",
        "remedy_safety": "manual_only",
        "remediation": {
          "steps": [
            "Verify the ConfigMap or Secret name in the volume reference matches an existing resource",
            "Create the missing ConfigMap/Secret or correct the volume reference"
          ],
          "commands": [
            "kubectl get configmap -n <namespace>",
            "kubectl get secret -n <namespace>"
          ]
        },
        "evidence_source": "native",
        "action_type": "human-decision",
        "next_step": {
          "action": "update_config",
          "description": "Verify the ConfigMap or Secret name in the volume reference matches an existing resource",
          "command": "kubectl get configmap -n <namespace>",
          "doc_ref": "cub-scan --explain CCVE-2025-4005"
        }
      },
      {
        "id": "CCVE-2025-4005",
        "name": "CCVE-2025-4005",
        "category": "CONFIGURATION",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "warning",
        "confidence": "unknown",
        "tool": "kubernetes",
        "resource": {
          "kind": "Deployment",
          "name": "consul-consul-mesh-gateway",
          "namespace": "consul"
        },
        "message": "Volume consul-ca-cert references Secret consul/consul-ca-cert which is not present in scanned documents",
        "remedy_type": "manual_only",
        "remedy_safety": "manual_only",
        "remediation": {
          "steps": [
            "Verify the ConfigMap or Secret name in the volume reference matches an existing resource",
            "Create the missing ConfigMap/Secret or correct the volume reference"
          ],
          "commands": [
            "kubectl get configmap -n <namespace>",
            "kubectl get secret -n <namespace>"
          ]
        },
        "evidence_source": "native",
        "action_type": "human-decision",
        "next_step": {
          "action": "update_config",
          "description": "Verify the ConfigMap or Secret name in the volume reference matches an existing resource",
          "command": "kubectl get configmap -n <namespace>",
          "doc_ref": "cub-scan --explain CCVE-2025-4005"
        }
      },
      {
        "id": "CCVE-2025-4005",
        "name": "CCVE-2025-4005",
        "category": "CONFIGURATION",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "warning",
        "confidence": "unknown",
        "tool": "kubernetes",
        "resource": {
          "kind": "Deployment",
          "name": "consul-consul-terminating-gateway",
          "namespace": "consul"
        },
        "message": "Volume consul-ca-cert references Secret consul/consul-ca-cert which is not present in scanned documents",
        "remedy_type": "manual_only",
        "remedy_safety": "manual_only",
        "remediation": {
          "steps": [
            "Verify the ConfigMap or Secret name in the volume reference matches an existing resource",
            "Create the missing ConfigMap/Secret or correct the volume reference"
          ],
          "commands": [
            "kubectl get configmap -n <namespace>",
            "kubectl get secret -n <namespace>"
          ]
        },
        "evidence_source": "native",
        "action_type": "human-decision",
        "next_step": {
          "action": "update_config",
          "description": "Verify the ConfigMap or Secret name in the volume reference matches an existing resource",
          "command": "kubectl get configmap -n <namespace>",
          "doc_ref": "cub-scan --explain CCVE-2025-4005"
        }
      },
      {
        "id": "CCVE-2025-4078",
        "name": "ClusterRole grants secrets read permissions",
        "category": "SECURITY",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "critical",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "ClusterRole",
          "name": "consul-consul-connect-injector",
          "namespace": "default"
        },
        "message": "ClusterRole grants secrets get/list, enabling credential exfiltration across namespaces",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Remove secrets get/list permissions from ClusterRoles that do not require credential access",
            "Scope secret access to namespaced Role bindings where possible"
          ],
          "commands": [
            "kubectl get clusterroles -o json | jq '.items[] | select(any(.rules[]?; any(.resources[]?; .==\"secrets\"))) | .metadata.name'"
          ]
        },
        "evidence_source": "native",
        "control_ids": [
          "CTRL-RBAC-0001"
        ],
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Remove secrets get/list permissions from ClusterRoles that do not require credential access",
          "command": "kubectl get clusterroles -o json | jq '.items[] | select(any(.rules[]?; any(.resources[]?; .==\"secrets\"))) | .metadata.name'",
          "doc_ref": "cub-scan --explain CCVE-2025-4078"
        }
      },
      {
        "id": "CCVE-2025-4078",
        "name": "ClusterRole grants secrets read permissions",
        "category": "SECURITY",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "critical",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "ClusterRole",
          "name": "consul-consul-webhook-cert-manager",
          "namespace": "default"
        },
        "message": "ClusterRole grants secrets get/list, enabling credential exfiltration across namespaces",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Remove secrets get/list permissions from ClusterRoles that do not require credential access",
            "Scope secret access to namespaced Role bindings where possible"
          ],
          "commands": [
            "kubectl get clusterroles -o json | jq '.items[] | select(any(.rules[]?; any(.resources[]?; .==\"secrets\"))) | .metadata.name'"
          ]
        },
        "evidence_source": "native",
        "control_ids": [
          "CTRL-RBAC-0001"
        ],
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Remove secrets get/list permissions from ClusterRoles that do not require credential access",
          "command": "kubectl get clusterroles -o json | jq '.items[] | select(any(.rules[]?; any(.resources[]?; .==\"secrets\"))) | .metadata.name'",
          "doc_ref": "cub-scan --explain CCVE-2025-4078"
        }
      }
    ],
    "provenance": {
      "source": "cub-scan",
      "source_version": "v0.7.3",
      "scan_time": "2026-08-24T16:00:34Z",
      "catalog_version": "risk-catalog-v1.json@7ff79a126ad9"
    },
    "pattern_bundle": {
      "schema_version": "bundle-manifest-v1",
      "version": "v0.7.3",
      "source_repo": "confighubai/confighub-scan",
      "manifest_sha256": "0405f6ffe21e567adf5d6a732d181c7f228194920456d046b4338baeb14de1a8",
      "catalog_sha256": "7ff79a126ad99bba2505fec8b2b7711c03f50eb362141128ec1c83e27a5036ba"
    },
    "input": {
      "object_count": 97,
      "object_set_sha256": "sha256:4423f0d86b67805edc18e2d19fed0fadfa75318e1afa373223edfef717a6d10e"
    }
  }
}
