Overview

FieldValue
ID1050
NameCreate SubjectAccessReviews (check arbitrary permissions)
Risk CategoryInformation Disclosure
Risk LevelMedium
Role TypeClusterRole
API Groupsauthorization.k8s.io
Resourcessubjectaccessreviews
Verbscreate
TagsInformationDisclosure RBACQuery

Description

Permits submitting SubjectAccessReview requests to check if an arbitrary user, group, or service account has specific permissions cluster-wide. This can be used for reconnaissance to understand the RBAC configuration and identify potential privilege escalation paths.