openshift-docs
Warn
Audited by Socket on Jul 28, 2026
1 alert found:
SecuritySecuritydocs/4.22/authentication/managing-oauth-access-tokens.md
MEDIUMSecurityMEDIUM
docs/4.22/authentication/managing-oauth-access-tokens.md
No embedded malware, obfuscation, or data-exfiltration behavior is present in this fragment; it is a static administrative procedure for creating a ClusterRoleBinding. However, it explicitly describes a security-critical authorization change by binding the system:unauthenticated group to a chosen ClusterRole, which can significantly expand unauthenticated capabilities if misused. This should be treated as a high-governance, high-risk configuration action requiring strict validation of the referenced ClusterRole and deployment controls.
Confidence: 72%Severity: 78%
Audit Metadata