sonarqube
Description
SonarQube is a self-managed, automatic code review tool that systematically helps you deliver clean code. As a core element of our Sonar solution, SonarQube integrates into your existing workflow and detects issues in your code to help you perform continuous code inspections of your projects. The tool analyses 30+ different programming languages and integrates into your CI pipeline and DevOps platform to ensure that your code meets high-quality standards.
- https://github.com/SonarSource/helm-chart-sonarqube/tree/master/charts/sonarqube
- https://github.com/SonarSource/docker-sonarqube
- https://github.com/SonarSource/sonarqube
Overview
Identity | Namespace | Automount | Secrets | Permissions | Workloads | Risk |
---|---|---|---|---|---|---|
sonarqube-ingress-nginx | default | ✅ | — | 25 | 1 | Critical |
sonarqube-ingress-nginx-admission | default | ✅ | — | 2 | 2 | Low |
Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.
Identities
🤖 sonarqube-ingress-nginx
Namespace: default
| Automount: ✅
🔑 Permissions (25)
Role | Resource | Verbs | Risk | Tags |
---|---|---|---|---|
Role sonarqube-ingress-nginx | core/secrets | get · list · watch | Critical | CredentialAccess DataExposure InformationDisclosure SecretAccess |
Role sonarqube-ingress-nginx | core/configmaps | get · list · watch | Medium | ConfigMapAccess DataExposure InformationDisclosure |
ClusterRole sonarqube-ingress-nginx | core/configmaps | list · watch | Low | |
ClusterRole sonarqube-ingress-nginx | core/endpoints | list · watch | Low | |
Role sonarqube-ingress-nginx | core/endpoints | get · list · watch | Low | |
ClusterRole sonarqube-ingress-nginx | discovery.k8s.io/endpointslices | get · list · watch | Low | |
Role sonarqube-ingress-nginx | discovery.k8s.io/endpointslices | get · list · watch | Low | |
ClusterRole sonarqube-ingress-nginx | core/events | create · patch | Low | |
Role sonarqube-ingress-nginx | core/events | create · patch | Low | |
ClusterRole sonarqube-ingress-nginx | networking.k8s.io/ingressclasses | get · list · watch | Low | |
Role sonarqube-ingress-nginx | networking.k8s.io/ingressclasses | get · list · watch | Low | |
ClusterRole sonarqube-ingress-nginx | networking.k8s.io/ingresses | get · list · watch | Low | |
Role sonarqube-ingress-nginx | networking.k8s.io/ingresses | get · list · watch | Low | |
ClusterRole sonarqube-ingress-nginx | networking.k8s.io/ingresses/status | update | Low | |
Role sonarqube-ingress-nginx | networking.k8s.io/ingresses/status | update | Low | |
ClusterRole sonarqube-ingress-nginx | coordination.k8s.io/leases | list · watch | Low | |
Role sonarqube-ingress-nginx | coordination.k8s.io/leases | create · get · update | Low | |
ClusterRole sonarqube-ingress-nginx | core/namespaces | list · watch | Low | ClusterStructure InformationDisclosure Reconnaissance |
Role sonarqube-ingress-nginx | core/namespaces | get | Low | |
ClusterRole sonarqube-ingress-nginx | core/nodes | get · list · watch | Low | |
ClusterRole sonarqube-ingress-nginx | core/pods | list · watch | Low | |
Role sonarqube-ingress-nginx | core/pods | get · list · watch | Low | |
ClusterRole sonarqube-ingress-nginx | core/secrets | list · watch | Low | |
ClusterRole sonarqube-ingress-nginx | core/services | get · list · watch | Low | |
Role sonarqube-ingress-nginx | core/services | get · list · watch | Low |
⚠️ Potential Abuse (4)
The following security risks were found based on the above permissions:
📦 Workloads (1)
Kind | Name | Container | Image |
---|---|---|---|
Deployment | sonarqube-ingress-nginx-controller | controller | registry.k8s.io/ingress-nginx/controller:v1.12.1@sha256:d2fbc4ec70d8aa2050dd91a91506e998765e86c96f32cffb56c503c9c34eed5b |
🤖 sonarqube-ingress-nginx-admission
Namespace: default
| Automount: ✅
🔑 Permissions (2)
Role | Resource | Verbs | Risk | Tags |
---|---|---|---|---|
Role sonarqube-ingress-nginx-admission | core/secrets | create · get | Low | |
ClusterRole sonarqube-ingress-nginx-admission | admissionregistration.k8s.io/validatingwebhookconfigurations | get · update | Low |
⚠️ Potential Abuse (1)
The following security risks were found based on the above permissions:
📦 Workloads (2)
Kind | Name | Container | Image |
---|---|---|---|
Job | sonarqube-ingress-nginx-admission-create | create | registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.5.2@sha256:e8825994b7a2c7497375a9b945f386506ca6a3eda80b89b74ef2db743f66a5ea |
Job | sonarqube-ingress-nginx-admission-patch | patch | registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.5.2@sha256:e8825994b7a2c7497375a9b945f386506ca6a3eda80b89b74ef2db743f66a5ea |