Over-permissive roles

The most common escalation is simply a role that grants too much. Wildcards (* resources or verbs), secrets read, pods/exec, and write access to roles or rolebindings are each enough to climb. Enumerate your effective rights and look for these.

bash
kubectl auth can-i --list
kubectl auth can-i get secrets
kubectl auth can-i create pods
kubectl auth can-i '*' '*'                 # wildcard = effectively admin in scope

Exploitation notes#

  • get secrets yields other identities' tokens, often a shortcut straight to a more privileged service account.
  • create pods or pods/exec escalates through the node, see Pod creation to node.
  • Write access to roles or bindings is self-escalation, bounded by the escalate and bind guards in Escalate and bind verbs.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more