You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Rename the ClusterRole 'manager-role' and ClusterRoleBinding 'manager-rolebinding' to 'securecodebox-manager-role' and 'securecodebox-manager-rolebinding', respectively, because the original names are too generic and could collide with other projects in the same cluster.
Signed-off-by: Boris Shek <boris.shek@iteratec.com>
"mitigation": "Remove write permission verbs for resource 'roles' and 'rolebindings'",
100089
-
"name": "Do not allow management of RBAC resources(ClusterRole 'manager-role' should not have access to resources ["roles", "rolebindings"] for verbs ["create", "update", "delete", "deletecollection", "impersonate", "*"])",
100089
+
"name": "Do not allow management of RBAC resources(ClusterRole 'securecodebox-manager-role' should not have access to resources ["roles", "rolebindings"] for verbs ["create", "update", "delete", "deletecollection", "impersonate", "*"])",
100090
100090
"references": [
100091
100091
{
100092
100092
"type": "URL",
@@ -100102,7 +100102,7 @@ and the severity is therefore considered low.",
"mitigation": "Remove write permission verbs for resource 'roles' and 'rolebindings'",
100118
-
"name": "Do not allow management of RBAC resources(ClusterRole 'manager-role' should not have access to resources ["roles", "rolebindings"] for verbs ["create", "update", "delete", "deletecollection", "impersonate", "*"])",
100118
+
"name": "Do not allow management of RBAC resources(ClusterRole 'securecodebox-manager-role' should not have access to resources ["roles", "rolebindings"] for verbs ["create", "update", "delete", "deletecollection", "impersonate", "*"])",
100119
100119
"references": [
100120
100120
{
100121
100121
"type": "URL",
@@ -152880,7 +152880,7 @@ and the severity is therefore considered low.",
"mitigation": "Remove write permission verbs for resource 'roles' and 'rolebindings'",
152925
-
"name": "Do not allow management of RBAC resources(ClusterRole 'manager-role' should not have access to resources ["roles", "rolebindings"] for verbs ["create", "update", "delete", "deletecollection", "impersonate", "*"])",
152925
+
"name": "Do not allow management of RBAC resources(ClusterRole 'securecodebox-manager-role' should not have access to resources ["roles", "rolebindings"] for verbs ["create", "update", "delete", "deletecollection", "impersonate", "*"])",
152926
152926
"references": [
152927
152927
{
152928
152928
"type": "URL",
@@ -152938,7 +152938,7 @@ and the severity is therefore considered low.",
"mitigation": "Remove write permission verbs for resource 'roles' and 'rolebindings'",
152954
-
"name": "Do not allow management of RBAC resources(ClusterRole 'manager-role' should not have access to resources ["roles", "rolebindings"] for verbs ["create", "update", "delete", "deletecollection", "impersonate", "*"])",
152954
+
"name": "Do not allow management of RBAC resources(ClusterRole 'securecodebox-manager-role' should not have access to resources ["roles", "rolebindings"] for verbs ["create", "update", "delete", "deletecollection", "impersonate", "*"])",
"Title": "Do not allow management of RBAC resources",
46942
46942
"Description": "An effective level of access equivalent to cluster-admin should not be provided.",
46943
-
"Message": "ClusterRole 'manager-role' should not have access to resources [\"roles\", \"rolebindings\"] for verbs [\"create\", \"update\", \"delete\", \"deletecollection\", \"impersonate\", \"*\"]",
46943
+
"Message": "ClusterRole 'securecodebox-manager-role' should not have access to resources [\"roles\", \"rolebindings\"] for verbs [\"create\", \"update\", \"delete\", \"deletecollection\", \"impersonate\", \"*\"]",
46944
46944
"Namespace": "builtin.kubernetes.KSV050",
46945
46945
"Query": "data.builtin.kubernetes.KSV050.deny",
46946
46946
"Resolution": "Remove write permission verbs for resource 'roles' and 'rolebindings'",
@@ -47050,7 +47050,7 @@
47050
47050
"AVDID": "AVD-KSV-0050",
47051
47051
"Title": "Do not allow management of RBAC resources",
47052
47052
"Description": "An effective level of access equivalent to cluster-admin should not be provided.",
47053
-
"Message": "ClusterRole 'manager-role' should not have access to resources [\"roles\", \"rolebindings\"] for verbs [\"create\", \"update\", \"delete\", \"deletecollection\", \"impersonate\", \"*\"]",
47053
+
"Message": "ClusterRole 'securecodebox-manager-role' should not have access to resources [\"roles\", \"rolebindings\"] for verbs [\"create\", \"update\", \"delete\", \"deletecollection\", \"impersonate\", \"*\"]",
47054
47054
"Namespace": "builtin.kubernetes.KSV050",
47055
47055
"Query": "data.builtin.kubernetes.KSV050.deny",
47056
47056
"Resolution": "Remove write permission verbs for resource 'roles' and 'rolebindings'",
"Title": "Do not allow management of RBAC resources",
47049
47049
"Description": "An effective level of access equivalent to cluster-admin should not be provided.",
47050
-
"Message": "ClusterRole 'manager-role' should not have access to resources [\"roles\", \"rolebindings\"] for verbs [\"create\", \"update\", \"delete\", \"deletecollection\", \"impersonate\", \"*\"]",
47050
+
"Message": "ClusterRole 'securecodebox-manager-role' should not have access to resources [\"roles\", \"rolebindings\"] for verbs [\"create\", \"update\", \"delete\", \"deletecollection\", \"impersonate\", \"*\"]",
47051
47051
"Namespace": "builtin.kubernetes.KSV050",
47052
47052
"Query": "data.builtin.kubernetes.KSV050.deny",
47053
47053
"Resolution": "Remove write permission verbs for resource 'roles' and 'rolebindings'",
@@ -47157,7 +47157,7 @@
47157
47157
"AVDID": "AVD-KSV-0050",
47158
47158
"Title": "Do not allow management of RBAC resources",
47159
47159
"Description": "An effective level of access equivalent to cluster-admin should not be provided.",
47160
-
"Message": "ClusterRole 'manager-role' should not have access to resources [\"roles\", \"rolebindings\"] for verbs [\"create\", \"update\", \"delete\", \"deletecollection\", \"impersonate\", \"*\"]",
47160
+
"Message": "ClusterRole 'securecodebox-manager-role' should not have access to resources [\"roles\", \"rolebindings\"] for verbs [\"create\", \"update\", \"delete\", \"deletecollection\", \"impersonate\", \"*\"]",
47161
47161
"Namespace": "builtin.kubernetes.KSV050",
47162
47162
"Query": "data.builtin.kubernetes.KSV050.deny",
47163
47163
"Resolution": "Remove write permission verbs for resource 'roles' and 'rolebindings'",
0 commit comments