zabbix
v7.0.12
1 Service Accounts
2 Workloads
18 Bindings
1 Critical
1 Medium
16 Low
Description
Zabbix is a mature and effortless enterprise-class open source monitoring solution for network monitoring and application monitoring of millions of metrics.
Overview
| Identity | Namespace | Automount | Secrets | Permissions | Workloads | Risk |
|---|---|---|---|---|---|---|
zabbix | default | ✅ | — | 18 | 6 | Critical |
Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.
Identities
🤖 zabbix
Namespace: default | Automount: ✅
🔑 Permissions (18)
| Role | Resource | Verbs | Risk | Tags |
|---|---|---|---|---|
ClusterRole zabbix | core/nodes/proxy | get | Critical | ClusterAdminAccess CodeExecution ElevationOfPrivilege LateralMovement (+1 more) |
ClusterRole zabbix | core/componentstatuses | get · list | Medium | ControlPlaneDisruption InformationDisclosure Reconnaissance |
ClusterRole zabbix | batch/cronjobs | get · list | Low | |
ClusterRole zabbix | apps/daemonsets | get · list | Low | |
ClusterRole zabbix | extensions/daemonsets | get · list | Low | |
ClusterRole zabbix | apps/deployments | get · list | Low | |
ClusterRole zabbix | extensions/deployments | get · list | Low | |
ClusterRole zabbix | core/endpoints | get · list | Low | |
ClusterRole zabbix | core/events | get · list | Low | |
ClusterRole zabbix | batch/jobs | get · list | Low | |
ClusterRole zabbix | core/namespaces | get · list | Low | |
ClusterRole zabbix | core/nodes | get · list | Low | |
ClusterRole zabbix | core/nodes/metrics | get | Low | |
ClusterRole zabbix | core/nodes/spec | get | Low | |
ClusterRole zabbix | core/nodes/stats | get | Low | |
ClusterRole zabbix | core/pods | get · list | Low | |
ClusterRole zabbix | core/services | get · list | Low | |
ClusterRole zabbix | apps/statefulsets | get · list | Low |
⚠️ Potential Abuse (3)
The following security risks were found based on the above permissions:
📦 Workloads (6)
| Kind | Name | Container | Image |
|---|---|---|---|
| CronJob | zabbix-nodesclean | hanodes-autoclean | postgres:16 |
| Deployment | zabbix-zabbix-server | zabbix-agent | zabbix/zabbix-agent2:ubuntu-7.0.16 |
| Deployment | zabbix-zabbix-server | zabbix-server | zabbix/zabbix-server-pgsql:ubuntu-7.0.16 |
| Deployment | zabbix-zabbix-web | zabbix-web | zabbix/zabbix-web-nginx-pgsql:ubuntu-7.0.16 |
| Deployment | zabbix-zabbix-webservice | zabbix-webservice | zabbix/zabbix-web-service:ubuntu-7.0.16 |
| StatefulSet | zabbix-postgresql | postgresql | postgres:16 |