Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-84199

Опубликовано: 01 сент. 2026
Источник: redhat
CVSS3: 7.7
EPSS Низкий

Описание

Kyverno before 1.16.2 contains a server-side request forgery (SSRF) vulnerability in the APICall feature. The URL field in a Policy's ServiceCall configuration is not validated, so a user with namespace-level Policy creation permissions can direct Kyverno to make HTTP requests to arbitrary internal resources (e.g., cloud metadata endpoints such as 169.254.169.254 or other tenants' resources). Because Kyverno executes these requests using its cluster-wide high-privilege ServiceAccount (a Confused Deputy problem), the responses—potentially including other tenants' secrets and cloud IAM credentials—are returned in the PolicyReport and can be read by the attacker, breaking multi-tenant isolation.

A flaw was found in Kyverno. A Server-Side Request Forgery (SSRF) vulnerability exists in the APICall feature due to improper validation of the URL field in a Policy's ServiceCall configuration. A user with namespace-level Policy creation permissions can exploit this to direct Kyverno to make HTTP requests to arbitrary internal resources. This allows the attacker to access sensitive information, such as cloud metadata endpoints or other tenants' secrets and cloud IAM credentials, breaking multi-tenant isolation.

Отчет

Important: Kyverno in Konflux is vulnerable to information disclosure via Server-Side Request Forgery. A user with namespace-level policy creation permissions can exploit an unvalidated URL in the APICall feature to access sensitive internal resources, including cloud metadata and other tenants' credentials, due to Kyverno's cluster-wide high-privilege ServiceAccount, thereby compromising multi-tenant isolation.

Меры по смягчению последствий

Exploitation of this flaw requires the ability to create or modify Kyverno Policy, ClusterPolicy, or GlobalContextEntry resources. The primary mitigation is to remove policy-authoring permissions from untrusted and namespace-scoped users: restrict create, update, and patch on policies.kyverno.io, clusterpolicies.kyverno.io, and globalcontextentries.kyverno.io to cluster administrators, and audit any Role or ClusterRole that grants these verbs to tenant service accounts.

Дополнительная информация

Статус:

Important
Дефект:
CWE-918
https://bugzilla.redhat.com/show_bug.cgi?id=2526877github.com/kyverno/kyverno: Kyverno: Information Disclosure via Server-Side Request Forgery in APICall Feature

EPSS

Процентиль: 18%
0.0026
Низкий

7.7 High

CVSS3

Связанные уязвимости

CVSS3: 7.7
nvd
15 дней назад

Kyverno before 1.16.2 contains a server-side request forgery (SSRF) vulnerability in the APICall feature. The URL field in a Policy's ServiceCall configuration is not validated, so a user with namespace-level Policy creation permissions can direct Kyverno to make HTTP requests to arbitrary internal resources (e.g., cloud metadata endpoints such as 169.254.169.254 or other tenants' resources). Because Kyverno executes these requests using its cluster-wide high-privilege ServiceAccount (a Confused Deputy problem), the responses—potentially including other tenants' secrets and cloud IAM credentials—are returned in the PolicyReport and can be read by the attacker, breaking multi-tenant isolation.

CVSS3: 7.7
github
15 дней назад

Kyverno before 1.16.2 contains a server-side request forgery (SSRF) vulnerability in the APICall feature. The URL field in a Policy's ServiceCall configuration is not validated, so a user with namespace-level Policy creation permissions can direct Kyverno to make HTTP requests to arbitrary internal resources (e.g., cloud metadata endpoints such as 169.254.169.254 or other tenants' resources). Because Kyverno executes these requests using its cluster-wide high-privilege ServiceAccount (a Confused Deputy problem), the responses—potentially including other tenants' secrets and cloud IAM credentials—are returned in the PolicyReport and can be read by the attacker, breaking multi-tenant isolation.

EPSS

Процентиль: 18%
0.0026
Низкий

7.7 High

CVSS3