Overview

FieldValue
ID1034
NameManage Deployments in a namespace (potential for privileged pod execution)
Risk CategoryElevation of Privilege
Risk LevelHigh
Role TypeRole
API Groupsapps
Resourcesdeployments
Verbscreate, update, patch, delete
TagsPersistence PotentialPrivilegeEscalation Tampering WorkloadLifecycle

Description

Grants permission to create, update, or delete Deployments within a specific namespace. This can be used to deploy pods with privileged settings within that namespace, potentially leading to privilege escalation, persistence, and tampering with applications.