Description

The Kubedoop Listener Operator

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
listener-operatordefault175Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 listener-operator

Namespace: default  |  Automount:

🔑 Permissions (17)

RoleResourceVerbsRiskTags
ClusterRole listener-operatorcore/nodescreate · get · list · patch · update · watchCriticalDenialOfService NodeAccess PotentialPrivilegeEscalation Tampering
ClusterRole listener-operatorcore/podscreate · get · list · patch · update · watchCriticalLateralMovement Persistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering (+1 more)
ClusterRole listener-operatorcore/servicescreate · delete · get · list · patch · update · watchCriticalDenialOfService NetworkManipulation ServiceExposure Tampering
ClusterRole listener-operatorcore/eventscreate · get · list · patch · update · watchMediumInformationDisclosure OperationalData Reconnaissance
ClusterRole listener-operatorstorage.k8s.io/csidriversget · list · patch · watchLow
ClusterRole listener-operatorcore/endpointsget · list · watchLow
ClusterRole listener-operatorlisteners.kubedoop.dev/listenerclassescreate · delete · get · list · patch · update · watchLow
ClusterRole listener-operatorlisteners.kubedoop.dev/listenerclasses/finalizersupdateLow
ClusterRole listener-operatorlisteners.kubedoop.dev/listenerclasses/statusget · patch · updateLow
ClusterRole listener-operatorlisteners.kubedoop.dev/listenercsiscreate · delete · get · list · patch · update · watchLow
ClusterRole listener-operatorlisteners.kubedoop.dev/listenercsis/finalizersupdateLow
ClusterRole listener-operatorlisteners.kubedoop.dev/listenerscreate · delete · get · list · patch · update · watchLow
ClusterRole listener-operatorlisteners.kubedoop.dev/listeners/finalizersupdateLow
ClusterRole listener-operatorlisteners.kubedoop.dev/listeners/statusget · patch · updateLow
ClusterRole listener-operatorcore/persistentvolumeclaimsget · list · watchLow
ClusterRole listener-operatorcore/persistentvolumescreate · delete · get · list · patch · update · watchLow
ClusterRole listener-operatorstorage.k8s.io/storageclassesget · list · patch · watchLow

⚠️ Potential Abuse (9)

The following security risks were found based on the above permissions:

📦 Workloads (5)

KindNameContainerImage
DaemonSetlistener-operator-daemonsetcsi-driverquay.io/zncdatadev/listener-csi-driver:0.1.0
DaemonSetlistener-operator-daemonsetcsi-provisionerregistry.k8s.io/sig-storage/csi-provisioner:v5.1.0
DaemonSetlistener-operator-daemonsetliveness-proberegistry.k8s.io/sig-storage/livenessprobe:v2.14.0
DaemonSetlistener-operator-daemonsetnode-driver-registrarregistry.k8s.io/sig-storage/csi-node-driver-registrar:v2.12.0
Deploymentlistener-operatorlistener-operatorquay.io/zncdatadev/listener-operator:0.1.0