Overview

FieldValue
ID1075
NameManage Services cluster-wide
Risk CategoryNetworkManipulation
Risk LevelCritical
Role TypeClusterRole
API Groupscore
Resourcesservices
Verbscreate, update, patch, delete
TagsDenialOfService NetworkManipulation ServiceExposure Tampering

Description

Allows creating, updating, or deleting Services in any namespace. This can be abused to expose internal applications, modify service types (e.g., ClusterIP to LoadBalancer), redirect traffic (by changing selectors), or cause denial of service.