Description

Crossplane is an open source Kubernetes add-on that enables platform teams to assemble infrastructure from multiple vendors, and expose higher level self-service APIs for application teams to consume.

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
rbac-managerdefault161Critical
crossplanedefault01

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 rbac-manager

Namespace: default  |  Automount:

🔑 Permissions (16)

RoleResourceVerbsRiskTags
ClusterRole crossplane-rbac-managerrbac.authorization.k8s.io/clusterrolebindings*CriticalBindingToPrivilegedRole ClusterAdminAccess ClusterWideAccess InformationDisclosure PrivilegeEscalation (+4 more)
ClusterRole crossplane-rbac-managerrbac.authorization.k8s.io/clusterrolesbind · create · escalate · get · list · patch · update · watchCriticalBindingToPrivilegedRole ClusterAdminAccess InformationDisclosure PrivilegeEscalation RBACManipulation (+2 more)
ClusterRole crossplane-rbac-managercore/configmapscreate · delete · get · list · patch · update · watchCriticalConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole crossplane-rbac-managercoordination.k8s.io/leasescreate · delete · get · list · patch · update · watchCriticalControlPlaneDisruption CriticalNamespace DenialOfService LeaderElectionAbuse Tampering
ClusterRole crossplane-rbac-managerrbac.authorization.k8s.io/rolescreate · escalate · get · list · patch · update · watchMediumInformationDisclosure RBACQuery Reconnaissance
ClusterRole crossplane-rbac-managerapiextensions.crossplane.io/compositeresourcedefinitionsget · list · watchLow
ClusterRole crossplane-rbac-managerapiextensions.crossplane.io/compositeresourcedefinitions/finalizersupdateLow
ClusterRole crossplane-rbac-managercoordination.k8s.io/configmapscreate · delete · get · list · patch · update · watchLow
ClusterRole crossplane-rbac-managerapiextensions.k8s.io/customresourcedefinitionsget · list · watchLow
ClusterRole crossplane-rbac-managerapps/deploymentsget · list · watchLow
ClusterRole crossplane-rbac-managercore/eventscreate · delete · patch · updateLow
ClusterRole crossplane-rbac-managercore/leasescreate · delete · get · list · patch · update · watchLow
ClusterRole crossplane-rbac-managercore/namespacesget · list · watchLowClusterStructure InformationDisclosure Reconnaissance
ClusterRole crossplane-rbac-managercore/namespaces/finalizersupdateLow
ClusterRole crossplane-rbac-managerpkg.crossplane.io/providerrevisionsget · list · watchLow
ClusterRole crossplane-rbac-managerpkg.crossplane.io/providerrevisions/finalizersupdateLow

⚠️ Potential Abuse (13)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentcrossplane-rbac-managercrossplanexpkg.crossplane.io/crossplane/crossplane:v1.20.0

🤖 crossplane

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (1)

KindNameContainerImage
Deploymentcrossplanecrossplanexpkg.crossplane.io/crossplane/crossplane:v1.20.0