Skip to content

Commit a5d30ff

Browse files
authored
Added "nodes/proxy" permission as risky (#29)
1 parent cb2afeb commit a5d30ff

File tree

1 file changed

+14
-0
lines changed

1 file changed

+14
-0
lines changed

risky_roles.yaml

+14
Original file line numberDiff line numberDiff line change
@@ -289,6 +289,20 @@ items:
289289

290290
######################### REGION - HIGH Roles #########################
291291

292+
# Risk: Privilege Escalation from Node/Proxy
293+
# Verb: get, create
294+
# Resources: nodes/proxy
295+
296+
- kind: Role
297+
metadata:
298+
namespace: default
299+
name: risky-execute-command-node-proxy
300+
priority: HIGH
301+
rules:
302+
- apiGroups: ["*"]
303+
resources: ["nodes/proxy"]
304+
verbs: ["get", "create"]
305+
292306
# Risk: Allowing to create a malicious pod
293307
# Verb: create
294308
# Resources: deployments

0 commit comments

Comments
 (0)