Overview

FieldValue
ID1014
NameNode proxy access (Kubelet API)
Risk CategoryElevation of Privilege
Risk LevelCritical
Role TypeClusterRole
API Groupscore
Resourcesnodes/proxy
Verbsget, create, update, patch, delete
TagsClusterAdminAccess CodeExecution DataExposure LateralMovement NodeAccess (+1 more)

Description

Provides direct access to the Kubelet API on any node in the cluster. This is equivalent to cluster admin access, allowing an attacker to run commands on nodes, access pod logs, execute commands in containers, and retrieve sensitive information directly from the nodes, leading to full cluster compromise.