Skip to content

Minimize Access to Pod Creation

An XCCDF Rule

Description

The ability to create pods in a namespace can provide a number of opportunities for privilege escalation. Where applicable, remove create access to pod objects in the cluster.

Rationale

The ability to create pods in a cluster opens up the cluster for privilege escalation.

ID
xccdf_org.ssgproject.content_rule_rbac_pod_creation_access
Severity
Medium
References
Updated