gadget
v0.48.0
1 Service Accounts
1 Workloads
16 Bindings
1 Critical
7 High
8 Low
Description
Gadgets for debugging and introspecting apps
Overview
| Identity | Namespace | Automount | Secrets | Permissions | Workloads | Risk |
|---|---|---|---|---|---|---|
gadget | default | ❌ | — | 16 | 0 | Critical |
Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.
Identities
🤖 gadget
Namespace: default | Automount: ❌
🔑 Permissions (16)
| Role | Resource | Verbs | Risk | Tags |
|---|---|---|---|---|
ClusterRole gadget-cluster-role | core/nodes/proxy | get | Critical | ClusterAdminAccess CodeExecution ElevationOfPrivilege LateralMovement (+1 more) |
ClusterRole gadget-cluster-role | */cronjobs | get | High | ClusterWideAccess |
ClusterRole gadget-cluster-role | */daemonsets | get | High | ClusterWideAccess |
ClusterRole gadget-cluster-role | */deployments | get | High | ClusterWideAccess |
ClusterRole gadget-cluster-role | */jobs | get | High | ClusterWideAccess |
ClusterRole gadget-cluster-role | */replicasets | get | High | ClusterWideAccess |
ClusterRole gadget-cluster-role | */replicationcontrollers | get | High | ClusterWideAccess |
ClusterRole gadget-cluster-role | */statefulsets | get | High | ClusterWideAccess |
ClusterRole gadget-cluster-role | core/namespaces | get · list · watch | Low | ClusterStructure InformationDisclosure Reconnaissance |
ClusterRole gadget-cluster-role | core/nodes | get · list · watch | Low | |
ClusterRole gadget-cluster-role | core/pods | get · list · watch | Low | |
ClusterRole gadget-cluster-role | security-profiles-operator.x-k8s.io/seccompprofiles | create · list · watch | Low | |
ClusterRole gadget-cluster-role | core/services | list · watch | Low | |
ClusterRole gadget-cluster-role | gadget.kinvolk.io/traces | create · delete · deletecollection · get · list · patch · update · watch | Low | |
ClusterRole gadget-cluster-role | gadget.kinvolk.io/traces/status | create · delete · deletecollection · get · list · patch · update · watch | Low | |
ClusterRole gadget-cluster-role | security.openshift.io/securitycontextconstraints (restricted to: privileged) | use | Low | ResourceNameRestricted |
⚠️ Potential Abuse (4)
The following security risks were found based on the above permissions:
📦 Workloads (0)
No workloads use this ServiceAccount.