gcp-gke-configmap-data

ConfigMaps are plaintext and are frequently misused for passwords, API keys, and application configuration.

gcpcritical service: gcp:gke emits ContainsCredential

Where it sits

locationKubernetes CoreV1 readNamespacedConfigMap/listConfigMapForAllNamespaces.ConfigMap.{data,binaryData}.<value>
location kindconfig_field
data kindscredential password api_key access_key secret_key oauth_token source_code_secret
emits edgeContainsCredential
serviceGKE (gcp:gke)

Collection recipe

access modedata_plane
operationKubernetes CoreV1 readNamespacedConfigMap/listConfigMapForAllNamespaces
response pathConfigMap.{data,binaryData}.<value>
encodingmap
params{"name": "\u003cresource-name\u003e"}

Required permissions

container.clusters.get

References

move · open · esc close