Skip to content

Kubernetes template for checking service token permissions? #11545

Closed Answered by princechaddha
domwhewell-sage asked this question in Q&A
Discussion options

You must be logged in to vote

Hi @domwhewell-sage, the response time to this discussion was much longer than usual. Thank you for taking the time to open this discussion.

We don’t have a template to check the above scenario, but I wrote one. however, it hasn’t been validated yet.

id: k8s-svc-token-create-perm

info:
  name: Service Account Token Create Permission Check
  author: princechaddha
  severity: high
  description: Checks if pods use service accounts with create permissions and automounted tokens, which could enable pod breakout scenarios.
  impact: |
    Pods using service accounts with create permissions and automounted tokens could potentially create new resources, leading to privilege escalation and pod b…

Replies: 2 comments 1 reply

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
1 reply
@domwhewell-sage
Comment options

Answer selected by domwhewell-sage
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants