From aa8e0d667775cd47e04190620ec678ac17e0edcd Mon Sep 17 00:00:00 2001 From: Tabitha Sable <51767484+tabbysable@users.noreply.github.com> Date: Tue, 4 Aug 2020 14:23:42 -0500 Subject: [PATCH] Correct Privilege Escalation section --- .../en/docs/concepts/security/pod-security-standards.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/content/en/docs/concepts/security/pod-security-standards.md b/content/en/docs/concepts/security/pod-security-standards.md index 20574c8f91..38ce76b16c 100644 --- a/content/en/docs/concepts/security/pod-security-standards.md +++ b/content/en/docs/concepts/security/pod-security-standards.md @@ -209,11 +209,11 @@ well as lower-trust users.The following listed controls should be enforced/disal Privilege Escalation - Privilege escalation to root should not be allowed.
+ Privilege escalation (typically via SUID/SGID file permission bits) should not be allowed.

Restricted Fields:
- spec.containers[*].securityContext.privileged
- spec.initContainers[*].securityContext.privileged
-
Allowed Values: false, undefined/nil
+ spec.containers[*].securityContext.allowPrivilegeEscalation
+ spec.initContainers[*].securityContext.allowPrivilegeEscalation
+
Allowed Values: false