Description

vcluster - Virtual Kubernetes Clusters

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
vc-vclusterdefault162Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 vc-vcluster

Namespace: default  |  Automount:

🔑 Permissions (16)

RoleResourceVerbsRiskTags
Role vclustercore/secrets*CriticalCredentialAccess DataExposure InformationDisclosure NamespaceAdmin NamespaceWideAccess (+5 more)
Role vclustercore/configmaps*HighConfigMapAccess DataExposure InformationDisclosure NamespaceAdmin NamespaceWideAccess (+3 more)
Role vclustercore/endpoints*HighDenialOfService NamespaceAdmin NamespaceWideAccess NetworkManipulation Tampering (+2 more)
Role vclusternetworking.k8s.io/ingresses*HighDenialOfService NamespaceAdmin NamespaceWideAccess NetworkManipulation ServiceExposure (+2 more)
Role vclustercore/pods*HighLateralMovement NamespaceAdmin NamespaceWideAccess Persistence PotentialPrivilegeEscalation (+3 more)
Role vclustercore/pods/attach*HighCodeExecution LateralMovement NamespaceAdmin NamespaceWideAccess PodAttach (+2 more)
Role vclustercore/pods/exec*HighCodeExecution LateralMovement NamespaceAdmin NamespaceWideAccess PodExec (+2 more)
Role vclustercore/services*HighDenialOfService NamespaceAdmin NamespaceWideAccess NetworkManipulation ServiceExposure (+2 more)
Role vclustercore/events*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role vclustercore/persistentvolumeclaims*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role vclustercore/pods/log*MediumDataExposure InformationDisclosure LogAccess NamespaceAdmin NamespaceWideAccess (+1 more)
Role vclustercore/pods/portforward*MediumLateralMovement NamespaceAdmin NamespaceWideAccess NetworkManipulation PodPortForward (+1 more)
Role vclustercore/pods/proxy*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role vclustercore/services/proxy*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role vclustercore/namespacesget · list · watchLow
Role vclusterapps/statefulsetsget · list · watchLow

⚠️ Potential Abuse (15)

The following security risks were found based on the above permissions:

📦 Workloads (2)

KindNameContainerImage
StatefulSetvclustersyncerloftsh/vcluster:0.1.0
StatefulSetvclustervclusterrancher/k3s:v1.19.1-k3s1