Overview

FieldValue
ID1042
NameManage Jobs in a namespace (one-off privileged execution)
Risk CategoryElevation of Privilege
Risk LevelHigh
Role TypeRole
API Groupsbatch
Resourcesjobs
Verbscreate, update, patch, delete
TagsPotentialPrivilegeEscalation Tampering WorkloadLifecycle

Description

Permits creating, updating, or deleting Jobs within a specific namespace. This can be used to run a one-off pod, potentially with privileged settings, leading to code execution and potential privilege escalation within that namespace.