Overview

FieldValue
ID1073
NameManage Endpoints or EndpointSlices cluster-wide
Risk CategoryNetworkManipulation
Risk LevelCritical
Role TypeClusterRole
API Groupscore, discovery.k8s.io
Resourcesendpoints, endpointslices
Verbscreate, update, patch, delete, get, list
TagsDenialOfService ManInTheMiddle NetworkManipulation Tampering TrafficRedirection

Description

Allows creating, updating, or deleting Endpoints/EndpointSlices for services across all namespaces. This can be used to redirect traffic intended for legitimate services to malicious pods (Man-in-the-Middle), cause denial of service, or bypass network policies.