Kubetier
  1. Update pods/ephemeralcontainers to inject a debug container into an existing running Pod.

  2. The debug container runs in the target Pod context and can access the Pod's mounted volumes, ServiceAccount token, and selected process namespace depending on target/runtime support.

  3. Reaches any process, mount and token inside a privileged Pod already running.

    Not the same as kubectl debug node/<name>, which requires create pods and spawns a separate privileged Pod.

Rights needed, any one set:

CVE-2023-2727↗CVE-2023-2728↗

Note:

CVE-2023-2727 and CVE-2023-2728 were admission/policy bypasses involving ephemeral containers.

The base RBAC risk is the ability to inject code into an existing Pod.

K8s docs ↗