Manage ephemeral containers in a namespace
Elevation of Privilege
High
Overview
| Field | Value |
|---|---|
| ID | 1021 |
| Name | Manage ephemeral containers in a namespace |
| Risk Category | Elevation of Privilege |
| Risk Level | High |
| Role Type | Role |
| API Groups | core |
| Resources | pods/ephemeralcontainers |
| Verbs | update, patch |
| Tags | CodeExecution LateralMovement PotentialPrivilegeEscalation Tampering WorkloadExecution |
Description
Allows adding or modifying ephemeral containers in pods within a specific namespace. This enables injecting code into running pods in that namespace, potentially leading to code execution, lateral movement, tampering, and privilege escalation if sensitive pods are targeted.