Description

Open source continuous integration server. It supports multiple SCM tools including CVS, Subversion and Git. It can execute Apache Ant and Apache Maven-based projects as well as arbitrary scripts.

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
jenkinsdefault41High

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 jenkins

Namespace: default  |  Automount:

🔑 Permissions (4)

RoleResourceVerbsRiskTags
Role jenkins-schedule-agentscore/pods*HighLateralMovement NamespaceAdmin NamespaceWideAccess Persistence PotentialPrivilegeEscalation (+3 more)
Role jenkins-schedule-agentscore/pods/exec*HighCodeExecution LateralMovement NamespaceAdmin NamespaceWideAccess PodExec (+2 more)
Role jenkins-schedule-agentscore/persistentvolumeclaims*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role jenkins-schedule-agentscore/pods/log*MediumDataExposure InformationDisclosure LogAccess NamespaceAdmin NamespaceWideAccess (+1 more)

⚠️ Potential Abuse (5)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentjenkinsjenkinsjenkins/jenkins:lts