Namespaced pod exec
Elevation of Privilege
High
Overview
| Field | Value |
|---|---|
| ID | 1001 |
| Name | Namespaced pod exec |
| Risk Category | Elevation of Privilege |
| Risk Level | High |
| Role Type | Role |
| API Groups | core |
| Resources | pods/exec |
| Verbs | create |
| Tags | CodeExecution LateralMovement PodExec PotentialPrivilegeEscalation |
Description
Permits executing commands within pods in a specific namespace. This grants shell access to containers within that namespace, potentially leading to code execution, lateral movement within the namespace, and privilege escalation if sensitive workloads or service accounts are compromised.