Overview

FieldValue
ID1077
NameRead RBAC configuration cluster-wide
Risk CategoryInformation Disclosure
Risk LevelMedium
Role TypeClusterRole
API Groupsrbac.authorization.k8s.io
Resourcesclusterroles, roles, clusterrolebindings, rolebindings
Verbsget, list, watch
TagsInformationDisclosure RBACQuery Reconnaissance

Description

Allows listing and getting all ClusterRoles, Roles, ClusterRoleBindings, and RoleBindings. This provides full visibility into the cluster’s authorization model, aiding attackers in finding privilege escalation paths or understanding defenses.