Description

YugaWare is YugaByte Database’s Orchestration and Management console.

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
yugawaredefault135Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 yugaware

Namespace: default  |  Automount:

🔑 Permissions (13)

RoleResourceVerbsRiskTags
ClusterRole yugawarecore/nodes/proxycreate · get · list · watchCriticalAuthorizationBypass ClusterAdminAccess CodeExecution ElevationOfPrivilege LateralMovement (+1 more)
ClusterRole yugawarecore/podscreate · get · list · watchCriticalLateralMovement Persistence PotentialPrivilegeEscalation PrivilegeEscalation WorkloadExecution
ClusterRole yugawarecore/pods/execcreate · get · list · watchCriticalClusterWidePodExec CodeExecution ElevationOfPrivilege LateralMovement PodExec (+1 more)
ClusterRole yugawarecore/secretscreate · delete · get · list · patch · update · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure Persistence (+4 more)
ClusterRole yugawarecore/namespacescreate · delete · get · list · patch · update · watchHighClusterStructure DenialOfService InformationDisclosure NamespaceLifecycle Reconnaissance (+1 more)
ClusterRole yugawarecore/pods/portforwardcreate · delete · get · list · patch · update · watchHighClusterWidePodPortForward LateralMovement NetworkManipulation PodPortForward
ClusterRole yugawarecore/deploymentscreate · delete · get · list · update · watchLow
ClusterRole yugawareextensions/deploymentscreate · delete · get · list · update · watchLow
ClusterRole yugawarecore/endpointscreate · get · list · watchLow
ClusterRole yugawareextensions/ingressesget · list · watchLow
ClusterRole yugawarecore/nodescreate · get · list · watchLow
ClusterRole yugawarecore/servicescreate · delete · get · list · update · watchLow
ClusterRole yugawareextensions/servicescreate · delete · get · list · update · watchLow

⚠️ Potential Abuse (14)

The following security risks were found based on the above permissions:

📦 Workloads (5)

KindNameContainerImage
StatefulSetyugaware-yugawarednsmasqjaneczku/go-dnsmasq:release-1.0.7
StatefulSetyugaware-yugawarenginxnginx:1.17.4
StatefulSetyugaware-yugawarepostgrespostgres:11.5
StatefulSetyugaware-yugawareprometheusprom/prometheus:v2.2.1
StatefulSetyugaware-yugawareyugawarequay.io/yugabyte/yugaware:2.4.3.0-b6