Kubetier
← Permission Reference
T1

update pods/ephemeralcontainers

The pods/ephemeralcontainers subresource injects an ephemeral debug container into a running Pod, without recreating it.

This record covers the raw PUT form.

kubectl debug sends a PATCH, so it needs pods-ephemeralcontainers-patch; update alone is refused for it.

This does not create a node debug Pod.

kubectl debug node/<name> requires create on pods plus permissive admission controls.

CVE-2023-2727↗CVE-2023-2728↗

Note:

CVE-2023-2727 and CVE-2023-2728 were policy-bypass issues involving ephemeral containers; they are separate from the ordinary RBAC risk of injecting a debug container into an existing pod.

API Group
(core)
Scope
namespaced
Audit Level
RequestResponse

Escalation Paths

  1. Update pods/ephemeralcontainers to inject a debug container into an existing running Pod.

  2. The debug container runs in the target Pod context and can access the Pod's mounted volumes, ServiceAccount token, and selected process namespace depending on target/runtime support.

  3. Reaches any process, mount and token inside a privileged Pod already running.

    Not the same as kubectl debug node/<name>, which requires create pods and spawns a separate privileged Pod.

Additional rights needed:

none
CVE-2023-2727↗CVE-2023-2728↗

Note:

CVE-2023-2727 and CVE-2023-2728 were admission/policy bypasses involving ephemeral containers.

The base RBAC risk is the ability to inject code into an existing Pod.

K8s docs ↗
K8s docs ↗