Overview

FieldValue
ID1097
NameUpdate StatefulSet Scale (Resource Abuse/DoS)
Risk CategoryDenial of Service
Risk LevelHigh
Role TypeRole
API Groupsapps
Resourcesstatefulsets/scale
Verbsupdate, patch
TagsDataLoss DenialOfService ResourceModification Tampering WorkloadLifecycle

Description

Allows updating the ‘scale’ subresource of StatefulSets within a namespace. This can be abused to significantly increase or decrease the number of replicas for a stateful application, potentially leading to resource exhaustion, denial of service, data inconsistencies, or unexpected operational costs.