Overview

FieldValue
ID1047
NameCreate ServiceAccount Tokens
Risk CategorySpoofing
Risk LevelCritical
Role TypeRole
API Groupsauthentication.k8s.io
Resourcesserviceaccounts/token
Verbscreate
TagsCredentialAccess Impersonation PotentialPrivilegeEscalation Spoofing TokenCreation

Description

Allows creating tokens for ServiceAccounts within a specific namespace. If a ServiceAccount has powerful permissions, creating a token for it allows impersonating that ServiceAccount, leading to potential privilege escalation, credential access, and spoofing.