Description

HiveMQ Platform Operator Helm Chart (new)

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
hivemq-platform-operator-hivemq-platform-operatordefault161Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 hivemq-platform-operator-hivemq-platform-operator

Namespace: default  |  Automount:

🔑 Permissions (16)

RoleResourceVerbsRiskTags
ClusterRole hivemq-platform-operator-role-hivemq-platform-operatorcore/configmapscreate · delete · get · list · patch · update · watchCriticalConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole hivemq-platform-operator-role-hivemq-platform-operatorcore/podscreate · delete · get · list · patch · update · watchCriticalLateralMovement Persistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering (+1 more)
ClusterRole hivemq-platform-operator-role-hivemq-platform-operatorcore/pods/execcreate · get · watchCriticalClusterWidePodExec CodeExecution ElevationOfPrivilege LateralMovement PodExec (+1 more)
ClusterRole hivemq-platform-operator-role-hivemq-platform-operatorcore/secretscreate · delete · get · list · patch · update · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure Persistence (+4 more)
ClusterRole hivemq-platform-operator-role-hivemq-platform-operatorcore/servicescreate · delete · get · list · patch · update · watchCriticalDenialOfService NetworkManipulation ServiceExposure Tampering
ClusterRole hivemq-platform-operator-role-hivemq-platform-operatorapps/statefulsetscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole hivemq-platform-operator-role-hivemq-platform-operatorrbac.authorization.k8s.io/rolebindingscreate · delete · get · list · patch · update · watchHighBindingToPrivilegedRole InformationDisclosure PrivilegeEscalation RBACManipulation RBACQuery (+1 more)
ClusterRole hivemq-platform-operator-role-hivemq-platform-operatorrbac.authorization.k8s.io/rolescreate · delete · get · list · patch · update · watchHighInformationDisclosure PrivilegeEscalation RBACManipulation RBACQuery Reconnaissance
ClusterRole hivemq-platform-operator-role-hivemq-platform-operatorcore/serviceaccountscreate · delete · get · list · patch · update · watchHighIdentityManagement PotentialPrivilegeEscalation Tampering
ClusterRole hivemq-platform-operator-role-hivemq-platform-operatorrbac.authorization.k8s.io/clusterrolebindingsget · list · watchMediumInformationDisclosure RBACQuery Reconnaissance
ClusterRole hivemq-platform-operator-role-hivemq-platform-operatorrbac.authorization.k8s.io/clusterrolesget · list · watchMediumInformationDisclosure RBACQuery Reconnaissance
ClusterRole hivemq-platform-operator-role-hivemq-platform-operatorcore/eventscreate · delete · get · list · patch · update · watchMediumInformationDisclosure OperationalData Reconnaissance
ClusterRole hivemq-platform-operator-role-hivemq-platform-operatorapiextensions.k8s.io/customresourcedefinitionscreate · get · list · patch · update · watchLow
ClusterRole hivemq-platform-operator-role-hivemq-platform-operatorhivemq.com/hivemq-platformscreate · delete · get · list · patch · update · watchLow
ClusterRole hivemq-platform-operator-role-hivemq-platform-operatorhivemq.com/hivemq-platforms/finalizerscreate · delete · get · list · patch · update · watchLow
ClusterRole hivemq-platform-operator-role-hivemq-platform-operatorhivemq.com/hivemq-platforms/statuscreate · delete · get · list · patch · update · watchLow

⚠️ Potential Abuse (25)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymenthivemq-hivemq-platform-operatorhivemq-platform-operatordocker.io/hivemq/hivemq-platform-operator:1.7.1