Overview

FieldValue
ID1051
NameCreate LocalSubjectAccessReviews (check permissions in a namespace)
Risk CategoryInformation Disclosure
Risk LevelLow
Role TypeRole
API Groupsauthorization.k8s.io
Resourceslocalsubjectaccessreviews
Verbscreate
TagsInformationDisclosure RBACQuery

Description

Allows submitting LocalSubjectAccessReview requests to check if an arbitrary user, group, or service account has specific permissions within a particular namespace. This aids in reconnaissance of RBAC permissions within a limited scope.