Overview

FieldValue
ID1074
NameManage Endpoints or EndpointSlices in a namespace
Risk CategoryNetworkManipulation
Risk LevelHigh
Role TypeRole
API Groupscore, discovery.k8s.io
Resourcesendpoints, endpointslices
Verbscreate, update, patch, delete, get, list
TagsDenialOfService NetworkManipulation Tampering TrafficRedirection

Description

Permits creating, updating, or deleting Endpoints/EndpointSlices for services within a specific namespace. This can lead to traffic redirection, denial of service, or network policy bypass for applications within that namespace.