Overview

FieldValue
ID1053
NameCreate CertificateSigningRequests
Risk CategorySpoofing
Risk LevelMedium
Role TypeClusterRole
API Groupscertificates.k8s.io
Resourcescertificatesigningrequests
Verbscreate
TagsCSRCreation PotentialPrivilegeEscalation Spoofing

Description

Allows creating CertificateSigningRequests. While creating a CSR itself isn’t immediately dangerous, if an overly permissive or automated signer approves it, it can lead to the issuance of a certificate with unintended privileges, facilitating spoofing or potential privilege escalation.