Overview

FieldValue
ID1054
NameManage (get, list, watch, delete) CertificateSigningRequests
Risk CategoryInformation Disclosure
Risk LevelMedium
Role TypeClusterRole
API Groupscertificates.k8s.io
Resourcescertificatesigningrequests
Verbsget, list, watch, delete
TagsDenialOfService InformationDisclosure Tampering

Description

Permits viewing, listing, watching, or deleting CertificateSigningRequests. Viewing CSRs can disclose information about pending certificate requests. Deleting CSRs can cause denial of service by preventing legitimate certificates from being issued or renewed.

Abuse Scenarios

  1. List all CertificateSigningRequests.
kubectl get csr
  1. Delete a specific CertificateSigningRequest, preventing certificate issuance.
kubectl delete csr <csr-name>
# Example: kubectl delete csr my-app-csr