Overview

FieldValue
ID1011
NameRead secrets in a namespace
Risk CategoryInformation Disclosure
Risk LevelCritical
Role TypeRole
API Groupscore
Resourcessecrets
Verbsget, list, watch
TagsCredentialAccess DataExposure InformationDisclosure SecretAccess

Description

Permits reading all secrets within a specific namespace. Even though namespaced, this is critical as secrets store sensitive information like database credentials, API keys, and service account tokens, which can lead to data exposure and privilege escalation within or beyond the namespace.