Description

Open source continuous integration server. It supports multiple SCM tools including CVS, Subversion and Git. It can execute Apache Ant and Apache Maven-based projects as well as arbitrary scripts.

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
jenkinsdefault51High

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 jenkins

Namespace: default  |  Automount:

🔑 Permissions (5)

RoleResourceVerbsRiskTags
Role jenkins-schedule-agentscore/podscreate · delete · deletecollection · get · list · patch · update · watchHighLateralMovement Persistence PotentialPrivilegeEscalation Tampering WorkloadExecution
Role jenkins-schedule-agentscore/pods/execcreate · delete · deletecollection · get · list · patch · update · watchHighCodeExecution LateralMovement PodExec PotentialPrivilegeEscalation
Role jenkins-schedule-agentscore/pods/logget · list · watchMediumDataExposure InformationDisclosure LogAccess
Role jenkins-schedule-agentscore/eventsget · list · watchLow
Role jenkins-schedule-agentscore/persistentvolumeclaimscreate · delete · deletecollection · get · list · patch · update · watchLow

⚠️ Potential Abuse (5)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentjenkinsjenkinsjenkins/jenkins:lts