Overview

FieldValue
ID1031
NameEscalate privileges via ClusterRoles (escalate verb)
Risk CategoryElevation of Privilege
Risk LevelCritical
Role TypeClusterRole
API Groupsrbac.authorization.k8s.io
Resourcesclusterroles
Verbsescalate
TagsClusterAdminAccess PrivilegeEscalation RBACManipulation

Description

Permits using the ’escalate’ verb on ClusterRoles (or Roles). This allows a user to create or update a role with more permissions than they currently possess, up to the permissions defined in the role they are escalating, leading to direct privilege escalation.