Overview

FieldValue
ID1071
NameManage NetworkPolicies cluster-wide
Risk CategoryNetworkManipulation
Risk LevelCritical
Role TypeClusterRole
API Groupsnetworking.k8s.io
Resourcesnetworkpolicies
Verbscreate, update, patch, delete
TagsDenialOfService LateralMovement NetworkManipulation NetworkPolicyManagement Tampering

Description

Allows creating, modifying, or deleting NetworkPolicies in any namespace. This can be used to disable network segmentation, allow/deny traffic to sensitive pods, or isolate critical components, leading to information disclosure, lateral movement, or denial of service.