Description

Keeps security report resources updated

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
trivy-operatordefault361Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 trivy-operator

Namespace: default  |  Automount:

🔑 Permissions (36)

RoleResourceVerbsRiskTags
ClusterRole trivy-operatorcore/secretscreate · delete · get · list · update · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole trivy-operatorcore/configmapsget · list · watchHighConfigMapAccess DataExposure InformationDisclosure
ClusterRole trivy-operatorcore/pods/logget · list · watchHighClusterWideLogAccess DataExposure InformationDisclosure LogAccess
ClusterRole trivy-operatorrbac.authorization.k8s.io/clusterrolebindingsget · list · watchMediumInformationDisclosure RBACQuery Reconnaissance
ClusterRole trivy-operatorrbac.authorization.k8s.io/clusterrolesget · list · watchMediumInformationDisclosure RBACQuery Reconnaissance
Role trivy-operatorcore/configmapscreate · get · list · watchMediumConfigMapAccess DataExposure InformationDisclosure
ClusterRole trivy-operatorcore/resourcequotasget · list · watchMediumInformationDisclosure QuotaTampering Reconnaissance ResourceConfiguration
ClusterRole trivy-operatorrbac.authorization.k8s.io/rolebindingsget · list · watchMediumInformationDisclosure RBACQuery Reconnaissance
ClusterRole trivy-operatorrbac.authorization.k8s.io/rolesget · list · watchMediumInformationDisclosure RBACQuery Reconnaissance
ClusterRole trivy-operatoraquasecurity.github.io/clustercompliancedetailreportscreate · delete · get · list · update · watchLow
ClusterRole trivy-operatoraquasecurity.github.io/clustercompliancereportscreate · delete · get · list · update · watchLow
ClusterRole trivy-operatoraquasecurity.github.io/clustercompliancereports/statusupdateLow
ClusterRole trivy-operatoraquasecurity.github.io/clusterconfigauditreportscreate · delete · get · list · update · watchLow
ClusterRole trivy-operatoraquasecurity.github.io/clusterrbacassessmentreportscreate · delete · get · list · update · watchLow
ClusterRole trivy-operatoraquasecurity.github.io/configauditreportscreate · delete · get · list · update · watchLow
ClusterRole trivy-operatorbatch/cronjobsget · list · watchLow
ClusterRole trivy-operatorapiextensions.k8s.io/customresourcedefinitionsget · list · watchLow
ClusterRole trivy-operatorapps/daemonsetsget · list · watchLow
ClusterRole trivy-operatorapps/deploymentsget · list · watchLow
Role trivy-operator-leader-electioncore/eventscreateLow
ClusterRole trivy-operatoraquasecurity.github.io/exposedsecretreportscreate · delete · get · list · update · watchLow
ClusterRole trivy-operatornetworking.k8s.io/ingressesget · list · watchLow
ClusterRole trivy-operatorbatch/jobscreate · delete · get · list · watchLow
Role trivy-operator-leader-electioncoordination.k8s.io/leasescreate · get · updateLow
ClusterRole trivy-operatorcore/limitrangesget · list · watchLowInformationDisclosure Reconnaissance ResourceConfiguration
ClusterRole trivy-operatornetworking.k8s.io/networkpoliciesget · list · watchLow
ClusterRole trivy-operatorcore/nodesget · list · watchLow
ClusterRole trivy-operatorcore/podsget · list · watchLow
ClusterRole trivy-operatorpolicy/podsecuritypoliciesget · list · watchLow
ClusterRole trivy-operatoraquasecurity.github.io/rbacassessmentreportscreate · delete · get · list · update · watchLow
ClusterRole trivy-operatorapps/replicasetsget · list · watchLow
ClusterRole trivy-operatorcore/replicationcontrollersget · list · watchLow
ClusterRole trivy-operatorcore/serviceaccountscreate · get · list · update · watchLow
ClusterRole trivy-operatorcore/servicesget · list · watchLow
ClusterRole trivy-operatorapps/statefulsetsget · list · watchLow
ClusterRole trivy-operatoraquasecurity.github.io/vulnerabilityreportscreate · delete · get · list · update · watchLow

⚠️ Potential Abuse (11)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymenttrivy-operatortrivy-operatordocker.io/aquasec/trivy-operator:0.1.3