Description

Keeps security report resources updated

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
trivy-operatordefault431High

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 trivy-operator

Namespace: default  |  Automount:

🔑 Permissions (43)

RoleResourceVerbsRiskTags
ClusterRole trivy-operatorcore/configmapsget · list · watchHighConfigMapAccess DataExposure InformationDisclosure
ClusterRole trivy-operatorcore/pods/logget · listHighClusterWideLogAccess DataExposure InformationDisclosure LogAccess
ClusterRole trivy-operatorrbac.authorization.k8s.io/clusterrolebindingsget · list · watchMediumInformationDisclosure RBACQuery Reconnaissance
ClusterRole trivy-operatorrbac.authorization.k8s.io/clusterrolesget · list · watchMediumInformationDisclosure RBACQuery Reconnaissance
Role trivy-operatorcore/configmapscreate · get · list · watchMediumConfigMapAccess DataExposure InformationDisclosure
ClusterRole trivy-operatorcore/resourcequotasget · list · watchMediumInformationDisclosure QuotaTampering Reconnaissance ResourceConfiguration
ClusterRole trivy-operatorrbac.authorization.k8s.io/rolebindingsget · list · watchMediumInformationDisclosure RBACQuery Reconnaissance
ClusterRole trivy-operatorrbac.authorization.k8s.io/rolesget · list · watchMediumInformationDisclosure RBACQuery Reconnaissance
ClusterRole trivy-operatoraquasecurity.github.io/clustercompliancedetailreportscreate · delete · get · list · patch · update · watchLow
ClusterRole trivy-operatoraquasecurity.github.io/clustercompliancereportscreate · delete · get · list · patch · update · watchLow
ClusterRole trivy-operatoraquasecurity.github.io/clustercompliancereports/statusget · patch · updateLow
ClusterRole trivy-operatoraquasecurity.github.io/clusterconfigauditreportscreate · delete · get · list · patch · update · watchLow
ClusterRole trivy-operatoraquasecurity.github.io/clusterinfraassessmentreportscreate · delete · get · list · patch · update · watchLow
ClusterRole trivy-operatoraquasecurity.github.io/clusterrbacassessmentreportscreate · delete · get · list · patch · update · watchLow
ClusterRole trivy-operatoraquasecurity.github.io/clustersbomreportscreate · delete · get · list · patch · update · watchLow
ClusterRole trivy-operatoraquasecurity.github.io/clustervulnerabilityreportscreate · delete · get · list · patch · update · watchLow
ClusterRole trivy-operatoraquasecurity.github.io/configauditreportscreate · delete · get · list · patch · update · watchLow
ClusterRole trivy-operatorbatch/cronjobsget · list · watchLow
ClusterRole trivy-operatorapiextensions.k8s.io/customresourcedefinitionsget · list · watchLow
ClusterRole trivy-operatorapps/daemonsetsget · list · watchLow
ClusterRole trivy-operatorapps.openshift.io/deploymentconfigsget · list · watchLow
ClusterRole trivy-operatorapps/deploymentsget · list · watchLow
Role trivy-operator-leader-electioncore/eventscreateLow
ClusterRole trivy-operatoraquasecurity.github.io/exposedsecretreportscreate · delete · get · list · patch · update · watchLow
ClusterRole trivy-operatoraquasecurity.github.io/infraassessmentreportscreate · delete · get · list · patch · update · watchLow
ClusterRole trivy-operatornetworking.k8s.io/ingressesget · list · watchLow
ClusterRole trivy-operatorbatch/jobscreate · delete · get · list · watchLow
Role trivy-operator-leader-electioncoordination.k8s.io/leasescreate · get · updateLow
ClusterRole trivy-operatorcore/limitrangesget · list · watchLowInformationDisclosure Reconnaissance ResourceConfiguration
ClusterRole trivy-operatornetworking.k8s.io/networkpoliciesget · list · watchLow
ClusterRole trivy-operatorcore/nodesget · list · watchLow
ClusterRole trivy-operatorcore/nodes/proxygetLow
ClusterRole trivy-operatorcore/podsget · list · watchLow
ClusterRole trivy-operatoraquasecurity.github.io/rbacassessmentreportscreate · delete · get · list · patch · update · watchLow
ClusterRole trivy-operatorapps/replicasetsget · list · watchLow
ClusterRole trivy-operatorcore/replicationcontrollersget · list · watchLow
ClusterRole trivy-operatoraquasecurity.github.io/sbomreportscreate · delete · get · list · patch · update · watchLow
ClusterRole trivy-operatorcore/secretscreate · get · updateLow
Role trivy-operatorcore/secretscreate · delete · get · updateLow
ClusterRole trivy-operatorcore/serviceaccountsgetLow
ClusterRole trivy-operatorcore/servicesget · list · watchLow
ClusterRole trivy-operatorapps/statefulsetsget · list · watchLow
ClusterRole trivy-operatoraquasecurity.github.io/vulnerabilityreportscreate · delete · get · list · patch · update · watchLow

⚠️ Potential Abuse (9)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymenttrivy-operatortrivy-operatormirror.gcr.io/aquasec/trivy-operator:0.27.0