Skip to content

Kubernetes Service Account Token Abuse

service-account-token-abuse is a critical severity check in the devops category, written in go. Its source is templates/devops/kubernetes/service-account-token-abuse.go in cert-x-gen-templates.

Detects Kubernetes misconfigurations that expose service account tokens to unauthenticated or minimally-privileged attackers. Checks for: unauthenticated Secrets API access, Kubelet /pods endpoint token path exposure, token-based API pivoting to kube-system secrets, and default service account over-permission. Token extraction and lateral movement (pivoting) are simulated in read-only detection mode.

Field Value
Id service-account-token-abuse
Severity critical
Language go
Category devops
Author BugB Technologies
Template version not recorded
Confidence 95
CVSS not recorded
Weakness CWE-522
Tags kubernetes, service-account, token-abuse, secrets, kubelet, privilege-escalation, lateral-movement, k8s, cloud-native
Target kind not recorded
Oracle not recorded

Declared in the header. cxg parses @references and then discards it, and nothing at scan time reads it, so this is the only place the links a template cites are surfaced.

To see what the copy on your machine says about itself, and to confirm it is installed at all:

Terminal window
cxg template info service-account-token-abuse

The id it prints is the one to pass anywhere a template is selected. See cxg template for the rest of the subcommand, Scan a target for running a scan, and A match is not a finding for how to read what comes back.