Overview

FieldValue
ID1078
NameUse privileged PodSecurityPolicy (deprecated)
Risk CategoryElevation of Privilege
Risk LevelCritical
Role TypeClusterRole
API Groupspolicy, extensions
Resourcespodsecuritypolicies
Verbsuse
TagsDeprecatedFeature NodeAccess PodSecurityPolicy PrivilegeEscalation

Description

Allows a user/service account to use a specific PodSecurityPolicy (PSP) that may grant excessive privileges (e.g., hostPath mounts, privileged mode). If the PSP is overly permissive, this leads to direct privilege escalation by creating pods that use it. (Note: PSPs are deprecated in 1.21 and removed in 1.25).