Overview

FieldValue
ID1049
NameCreate TokenReviews (validate arbitrary tokens)
Risk CategoryInformation Disclosure
Risk LevelMedium
Role TypeClusterRole
API Groupsauthentication.k8s.io
Resourcestokenreviews
Verbscreate
TagsCredentialAccess InformationDisclosure RBACQuery

Description

Allows submitting TokenReview requests to the API server to validate arbitrary tokens. This can be used to probe the validity and attributes of tokens, potentially discovering active service account tokens or user tokens, leading to information disclosure about authentication.