The TokenRequest API issues short-lived tokens for service accounts. The permission create on the serviceaccounts/token subresource lets an identity mint a token for that account. If you can request tokens for a more privileged service account, you can become it.
kubectl auth can-i create serviceaccounts/token
# Mint a token for a target service account
kubectl create token <privileged-sa> -n <ns>
kubectl --token=<minted> auth can-i --list
Exploitation notes#
- This is the modern replacement for reading long-lived token secrets; the right to mint is the escalation, scoped to the service accounts you may act on.
- Combine with enumeration of which service accounts are privileged, then mint for the strongest one you are allowed.
- Minted tokens are time-bound, so use them promptly or re-mint; for durable access prefer CSR approval.