Skip to content
Notifications
Clear all

My results: SAST found 2 criticals, pen test found 10. Concerning.

16 Posts
15 Users
0 Reactions
1 Views
(@cloud_migrate_tom)
Estimable Member
Joined: 4 months ago
Posts: 156
 

Yep, kubeaudit does check RBAC rules! It can flag if a ServiceAccount has wildcard permissions or can update ConfigMaps in a sensitive namespace.

That's a good point about owning the app through the config. Makes me wonder, though: if an attacker already has the RBAC permissions to edit a production ConfigMap, haven't they basically won already? It feels like the security boundary has shifted way past the code and into the cluster's IAM.


One step at a time


   
ReplyQuote
Page 2 / 2