Description

DEPRECATED Wavefront is a high-performance streaming analytics platform for monitoring and optimizing your environment and applications.

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
wavefront-collectordefault171Critical
wavefront-kube-state-metricsdefault311Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 wavefront-kube-state-metrics

Namespace: default  |  Automount:

🔑 Permissions (31)

RoleResourceVerbsRiskTags
ClusterRole wavefront-kube-state-metrics-defaultcore/secretslist · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole wavefront-kube-state-metrics-defaultcore/configmapslist · watchHighConfigMapAccess DataExposure InformationDisclosure
ClusterRole wavefront-kube-state-metrics-defaultadmissionregistration.k8s.io/mutatingwebhookconfigurationslist · watchMediumInformationDisclosure Reconnaissance WebhookReconnaissance
ClusterRole wavefront-kube-state-metrics-defaultcore/resourcequotaslist · watchMediumInformationDisclosure QuotaTampering Reconnaissance ResourceConfiguration
ClusterRole wavefront-kube-state-metrics-defaultcertificates.k8s.io/certificatesigningrequestslist · watchLow
ClusterRole wavefront-kube-state-metrics-defaultbatch/cronjobslist · watchLow
ClusterRole wavefront-kube-state-metrics-defaultapps/daemonsetslist · watchLow
ClusterRole wavefront-kube-state-metrics-defaultextensions/daemonsetslist · watchLow
ClusterRole wavefront-kube-state-metrics-defaultapps/deploymentslist · watchLow
ClusterRole wavefront-kube-state-metrics-defaultextensions/deploymentslist · watchLow
ClusterRole wavefront-kube-state-metrics-defaultcore/endpointslist · watchLow
ClusterRole wavefront-kube-state-metrics-defaultautoscaling/horizontalpodautoscalerslist · watchLow
ClusterRole wavefront-kube-state-metrics-defaultextensions/ingresseslist · watchLow
ClusterRole wavefront-kube-state-metrics-defaultnetworking.k8s.io/ingresseslist · watchLow
ClusterRole wavefront-kube-state-metrics-defaultbatch/jobslist · watchLow
ClusterRole wavefront-kube-state-metrics-defaultcore/limitrangeslist · watchLowInformationDisclosure Reconnaissance ResourceConfiguration
ClusterRole wavefront-kube-state-metrics-defaultcore/namespaceslist · watchLowClusterStructure InformationDisclosure Reconnaissance
ClusterRole wavefront-kube-state-metrics-defaultnetworking.k8s.io/networkpolicieslist · watchLow
ClusterRole wavefront-kube-state-metrics-defaultcore/nodeslist · watchLow
ClusterRole wavefront-kube-state-metrics-defaultcore/persistentvolumeclaimslist · watchLow
ClusterRole wavefront-kube-state-metrics-defaultcore/persistentvolumeslist · watchLow
ClusterRole wavefront-kube-state-metrics-defaultpolicy/poddisruptionbudgetslist · watchLow
ClusterRole wavefront-kube-state-metrics-defaultcore/podslist · watchLow
ClusterRole wavefront-kube-state-metrics-defaultapps/replicasetslist · watchLow
ClusterRole wavefront-kube-state-metrics-defaultextensions/replicasetslist · watchLow
ClusterRole wavefront-kube-state-metrics-defaultcore/replicationcontrollerslist · watchLow
ClusterRole wavefront-kube-state-metrics-defaultcore/serviceslist · watchLow
ClusterRole wavefront-kube-state-metrics-defaultapps/statefulsetslist · watchLow
ClusterRole wavefront-kube-state-metrics-defaultstorage.k8s.io/storageclasseslist · watchLow
ClusterRole wavefront-kube-state-metrics-defaultstorage.k8s.io/volumeattachmentslist · watchLow
ClusterRole wavefront-kube-state-metrics-default-pspextensions/podsecuritypolicies (restricted to: wavefront-kube-state-metrics-default)useLowDeprecatedFeature NodeAccess PodSecurityPolicy PrivilegeEscalation ResourceNameRestricted

⚠️ Potential Abuse (11)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentwavefront-kube-state-metricskube-state-metricsdocker.io/bitnami/kube-state-metrics:2.8.2-debian-11-r14

🤖 wavefront-collector

Namespace: default  |  Automount:

🔑 Permissions (17)

RoleResourceVerbsRiskTags
ClusterRole wavefront-collectorcore/nodes/proxyget · list · watchCriticalAuthorizationBypass ClusterAdminAccess CodeExecution ElevationOfPrivilege LateralMovement (+1 more)
ClusterRole wavefront-collectorcore/secretsget · list · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole wavefront-collectorcore/configmapscreate · get · list · update · watchHighConfigMapAccess DataExposure InformationDisclosure
ClusterRole wavefront-collectorcore/eventsget · list · watchMediumInformationDisclosure OperationalData Reconnaissance
ClusterRole wavefront-collectorbatch/cronjobsget · list · watchLow
ClusterRole wavefront-collectorapps/daemonsetsget · list · watchLow
ClusterRole wavefront-collectorapps/deploymentsget · list · watchLow
ClusterRole wavefront-collectorautoscaling/horizontalpodautoscalersget · list · watchLow
ClusterRole wavefront-collectorbatch/jobsget · list · watchLow
ClusterRole wavefront-collectorcore/namespacesget · list · watchLowClusterStructure InformationDisclosure Reconnaissance
ClusterRole wavefront-collectorcore/nodesget · list · watchLow
ClusterRole wavefront-collectorcore/nodes/statsget · list · watchLow
ClusterRole wavefront-collectorcore/podsget · list · watchLow
ClusterRole wavefront-collectorapps/replicasetsget · list · watchLow
ClusterRole wavefront-collectorcore/replicationcontrollersget · list · watchLow
ClusterRole wavefront-collectorcore/servicesget · list · watchLow
ClusterRole wavefront-collectorapps/statefulsetsget · list · watchLow

⚠️ Potential Abuse (8)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
DaemonSetwavefront-collectorwavefront-collectordocker.io/bitnami/wavefront-kubernetes-collector:1.13.0-scratch-r16