Description

Commons operator of Kubedoop

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
commons-operatordefault61Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 commons-operator

Namespace: default  |  Automount:

🔑 Permissions (6)

RoleResourceVerbsRiskTags
ClusterRole commons-operatorcore/podsget · list · patch · update · watchCriticalPotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadExecution
ClusterRole commons-operatorcore/secretsget · list · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole commons-operatorcore/configmapsget · list · watchHighConfigMapAccess DataExposure InformationDisclosure
ClusterRole commons-operatorcore/nodesget · list · watchLow
ClusterRole commons-operatorcore/pods/evictioncreateLow
ClusterRole commons-operatorapps/statefulsetsget · list · patch · watchLow

⚠️ Potential Abuse (7)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentcommons-operatorcommons-operatorquay.io/zncdatadev/commons-operator:0.2.0