Overview

FieldValue
ID1085
NameCreate/Update ControllerRevisions (Potential Tampering)
Risk CategoryTampering
Risk LevelMedium
Role TypeRole
API Groupsapps
Resourcescontrollerrevisions
Verbscreate, update, patch
TagsControllerRevisionTampering Tampering WorkloadLifecycle

Description

Allows creating or updating ControllerRevisions. This could be abused to tamper with the history of workloads like Deployments or StatefulSets, potentially forcing rollbacks to vulnerable versions, manipulating state, or obscuring legitimate changes.