Overview

FieldValue
ID1083
NameList ValidatingWebhookConfigurations (Reconnaissance)
Risk CategoryInformation Disclosure
Risk LevelMedium
Role TypeClusterRole
API Groupsadmissionregistration.k8s.io
Resourcesvalidatingwebhookconfigurations
Verbslist, watch
TagsInformationDisclosure Reconnaissance WebhookReconnaissance

Description

Allows listing of ValidatingWebhookConfigurations cluster-wide. This reveals information about admission control mechanisms and security policies enforced, aiding attackers in understanding defense postures.

Abuse Scenarios

  1. List all ValidatingWebhookConfigurations.
kubectl get validatingwebhookconfigurations