Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m3cq-xcx9-3gvm

Опубликовано: 21 дек. 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

kyverno verifyImages rule bypass possible with malicious proxy/registry

Impact

Users of Kyverno on versions 1.8.3 or 1.8.4 who use verifyImages rules to verify container image signatures, and do not prevent use of unknown registries.

Patches

This issue has been fixed in version 1.8.5

Workarounds

Configure a Kyverno policy to restrict registries to a set of secure trusted image registries (sample).

References

Пакеты

Наименование

github.com/kyverno/kyverno

go
Затронутые версииВерсия исправления

>= 1.8.3, < 1.8.5

1.8.5

EPSS

Процентиль: 33%
0.00131
Низкий

8.1 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 8.1
nvd
около 3 лет назад

An image signature validation bypass vulnerability in Kyverno 1.8.3 and 1.8.4 allows a malicious image registry (or a man-in-the-middle attacker) to inject unsigned arbitrary container images into a protected Kubernetes cluster. This is fixed in 1.8.5. This has been fixed in 1.8.5 and mitigations are available for impacted releases.

EPSS

Процентиль: 33%
0.00131
Низкий

8.1 High

CVSS3

Дефекты

CWE-287