🚀 Submit a Challenge — SecDim AppSec Village CTF at DEF CON 34 and Win a ROG Xbox Ally

Privilege Escalation in Kubernetes

Processes with in container can gain additional privileges is if allowPrivilegeEscalation is not set.

Remediation

apiVersion: apps/v1
kind: Deployment
spec:
  template:
    spec:
      containers:
      - name: myContainer
        securityContext:
          allowPrivilegeEscalation: false

Metadata

  • Severity: high
  • Slug: privilege-escalation-in-kubernetes

CWEs

  • 250: Execution with Unnecessary Privileges

OWASP

  • A04:2021: Insecure Design

Available Labs

Select a language to explore available labs for this vulnerability.

No matching labs found

Try adjusting your language filter.

Try it yourself

Find, Hack and Fix Your First Vulnerability

Reading about security bugs is one thing — fixing one is how the skill sticks. Play a free challenge from the wargame, no setup required.