Description

Event based autoscaler for Azure Functions deployments on Kubernetes

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
keda-operatordefaultโŒโ€”162Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

๐Ÿค– keda-operator

Namespace: default ย |ย  Automount: โŒ

๐Ÿ”‘ Permissions (16)

RoleResourceVerbsRiskTags
ClusterRole keda-operatorcore/configmaps*CriticalClusterWideAccess ConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation (+2 more)
ClusterRole keda-operatorapps/deployments*CriticalClusterWideAccess Persistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering (+2 more)
ClusterRole keda-operatorcore/endpoints*CriticalClusterWideAccess DenialOfService ManInTheMiddle NetworkManipulation Tampering (+2 more)
ClusterRole keda-operatorbatch/jobs*CriticalClusterWideAccess PotentialPrivilegeEscalation PrivilegeEscalation Tampering WildcardPermission (+1 more)
ClusterRole keda-operatorcore/pods*CriticalClusterWideAccess LateralMovement Persistence PotentialPrivilegeEscalation PrivilegeEscalation (+3 more)
ClusterRole keda-operatorcore/secrets*CriticalClusterWideAccess ClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure (+6 more)
ClusterRole keda-operatorcore/services*CriticalClusterWideAccess DenialOfService NetworkManipulation ServiceExposure Tampering (+1 more)
ClusterRole keda-operatorkeda.k8s.io/**HighClusterWideAccess WildcardPermission
ClusterRole keda-operatorapps/deployments/finalizers*HighClusterWideAccess WildcardPermission
ClusterRole keda-operatorcore/external*HighClusterWideAccess WildcardPermission
ClusterRole keda-operatorautoscaling/horizontalpodautoscalers*HighClusterWideAccess WildcardPermission
ClusterRole keda-operatorcore/namespaces*HighClusterStructure ClusterWideAccess DenialOfService InformationDisclosure NamespaceLifecycle (+3 more)
ClusterRole keda-operatorapps/replicasets*HighClusterWideAccess WildcardPermission
ClusterRole keda-operatorcore/services/finalizers*HighClusterWideAccess WildcardPermission
ClusterRole keda-operatorcore/events*MediumClusterWideAccess InformationDisclosure OperationalData Reconnaissance WildcardPermission
ClusterRole keda-operatormonitoring.coreos.com/servicemonitorscreate ยท getLow

โš ๏ธ Potential Abuse (25)

The following security risks were found based on the above permissions:

๐Ÿ“ฆ Workloads (2)

KindNameContainerImage
Deploymentkeda-operatorkeda-operatordocker.io/kedacore/keda:1.1.0
Deploymentkeda-operatorkeda-operator-metrics-apiserverdocker.io/kedacore/keda-metrics-adapter:1.1.0