Description

Deploy the Bitwarden CRD Operator

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
bitwarden-crd-operatordefault111Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 bitwarden-crd-operator

Namespace: default  |  Automount:

🔑 Permissions (11)

RoleResourceVerbsRiskTags
ClusterRole bitwarden-crd-operator-rolecore/secretscreate · delete · get · list · patch · update · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure Persistence (+4 more)
ClusterRole bitwarden-crd-operator-rolelerentis.uploadfilter24.eu/bitwarden-secretscreate · delete · get · list · patch · update · watchLow
ClusterRole bitwarden-crd-operator-rolelerentis.uploadfilter24.eu/bitwarden-templatescreate · delete · get · list · patch · update · watchLow
ClusterRole bitwarden-crd-operator-roleapiextensions.k8s.io/customresourcedefinitionslist · watchLow
ClusterRole bitwarden-crd-operator-rolecore/eventscreateLow
ClusterRole bitwarden-crd-operator-roleadmissionregistration.k8s.io/v1/mutatingwebhookconfigurationscreate · patchLow
ClusterRole bitwarden-crd-operator-roleadmissionregistration.k8s.io/v1beta1/mutatingwebhookconfigurationscreate · patchLow
ClusterRole bitwarden-crd-operator-rolecore/namespaceslist · watchLowClusterStructure InformationDisclosure Reconnaissance
ClusterRole bitwarden-crd-operator-rolelerentis.uploadfilter24.eu/registry-credentialscreate · delete · get · list · patch · update · watchLow
ClusterRole bitwarden-crd-operator-roleadmissionregistration.k8s.io/v1/validatingwebhookconfigurationscreate · patchLow
ClusterRole bitwarden-crd-operator-roleadmissionregistration.k8s.io/v1beta1/validatingwebhookconfigurationscreate · patchLow

⚠️ Potential Abuse (6)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentbitwarden-crd-operatorbitwarden-crd-operatorghcr.io/lerentis/bitwarden-crd-operator:0.14.1