Description

A virtual kubernetes cluster

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
vc-virtualclusterdefault162Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 vc-virtualcluster

Namespace: default  |  Automount:

🔑 Permissions (16)

RoleResourceVerbsRiskTags
Role virtualclustercore/secrets*CriticalCredentialAccess DataExposure InformationDisclosure NamespaceAdmin NamespaceWideAccess (+5 more)
Role virtualclustercore/configmaps*HighConfigMapAccess DataExposure InformationDisclosure NamespaceAdmin NamespaceWideAccess (+3 more)
Role virtualclustercore/endpoints*HighDenialOfService NamespaceAdmin NamespaceWideAccess NetworkManipulation Tampering (+2 more)
Role virtualclusternetworking.k8s.io/ingresses*HighDenialOfService NamespaceAdmin NamespaceWideAccess NetworkManipulation ServiceExposure (+2 more)
Role virtualclustercore/pods*HighLateralMovement NamespaceAdmin NamespaceWideAccess Persistence PotentialPrivilegeEscalation (+3 more)
Role virtualclustercore/pods/attach*HighCodeExecution LateralMovement NamespaceAdmin NamespaceWideAccess PodAttach (+2 more)
Role virtualclustercore/pods/exec*HighCodeExecution LateralMovement NamespaceAdmin NamespaceWideAccess PodExec (+2 more)
Role virtualclustercore/services*HighDenialOfService NamespaceAdmin NamespaceWideAccess NetworkManipulation ServiceExposure (+2 more)
Role virtualclustercore/events*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role virtualclustercore/persistentvolumeclaims*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role virtualclustercore/pods/log*MediumDataExposure InformationDisclosure LogAccess NamespaceAdmin NamespaceWideAccess (+1 more)
Role virtualclustercore/pods/portforward*MediumLateralMovement NamespaceAdmin NamespaceWideAccess NetworkManipulation PodPortForward (+1 more)
Role virtualclustercore/pods/proxy*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role virtualclustercore/services/proxy*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role virtualclustercore/namespacesget · list · watchLow
Role virtualclusterapps/statefulsetsget · list · watchLow

⚠️ Potential Abuse (15)

The following security risks were found based on the above permissions:

📦 Workloads (2)

KindNameContainerImage
StatefulSetvirtualclustersyncerloftsh/virtual-cluster:0.0.28
StatefulSetvirtualclustervirtual-clusterrancher/k3s:v1.19.1-k3s1