Overview

FieldValue
ID1044
NameManage ValidatingWebhookConfigurations
Risk CategoryTampering
Risk LevelCritical
Role TypeClusterRole
API Groupsadmissionregistration.k8s.io
Resourcesvalidatingwebhookconfigurations
Verbscreate, update, patch, delete
TagsDenialOfService Tampering WebhookManipulation

Description

Allows control over ValidatingWebhookConfigurations, which can validate or reject API objects during admission. An attacker can use this to tamper with security policies (e.g., disable a validating webhook that enforces security best practices) or cause denial of service by rejecting legitimate requests.