Overview

FieldValue
ID1041
NameManage Jobs cluster-wide (one-off privileged execution)
Risk CategoryElevation of Privilege
Risk LevelCritical
Role TypeClusterRole
API Groupsbatch
Resourcesjobs
Verbscreate, update, patch, delete
TagsPrivilegeEscalation Tampering WorkloadLifecycle

Description

Allows creating, updating, or deleting Jobs across all namespaces. Jobs create one or more pods for batch tasks. This can be used to run a one-off pod with privileged settings, leading to code execution, privilege escalation, and tampering.