Overview

FieldValue
ID1084
NameList MutatingWebhookConfigurations (Reconnaissance)
Risk CategoryInformation Disclosure
Risk LevelMedium
Role TypeClusterRole
API Groupsadmissionregistration.k8s.io
Resourcesmutatingwebhookconfigurations
Verbslist, watch
TagsInformationDisclosure Reconnaissance WebhookReconnaissance

Description

Allows listing of MutatingWebhookConfigurations cluster-wide. This reveals information about how resources might be altered upon creation/update, aiding attackers in understanding automated modifications and potential vulnerabilities.

Abuse Scenarios

  1. List all MutatingWebhookConfigurations.
kubectl get mutatingwebhookconfigurations