Описание
Kyverno before 1.16.2 contains a server-side request forgery (SSRF) vulnerability in the APICall feature. The URL field in a Policy's ServiceCall configuration is not validated, so a user with namespace-level Policy creation permissions can direct Kyverno to make HTTP requests to arbitrary internal resources (e.g., cloud metadata endpoints such as 169.254.169.254 or other tenants' resources). Because Kyverno executes these requests using its cluster-wide high-privilege ServiceAccount (a Confused Deputy problem), the responses—potentially including other tenants' secrets and cloud IAM credentials—are returned in the PolicyReport and can be read by the attacker, breaking multi-tenant isolation.
A flaw was found in Kyverno. A Server-Side Request Forgery (SSRF) vulnerability exists in the APICall feature due to improper validation of the URL field in a Policy's ServiceCall configuration. A user with namespace-level Policy creation permissions can exploit this to direct Kyverno to make HTTP requests to arbitrary internal resources. This allows the attacker to access sensitive information, such as cloud metadata endpoints or other tenants' secrets and cloud IAM credentials, breaking multi-tenant isolation.
Отчет
Important: Kyverno in Konflux is vulnerable to information disclosure via Server-Side Request Forgery. A user with namespace-level policy creation permissions can exploit an unvalidated URL in the APICall feature to access sensitive internal resources, including cloud metadata and other tenants' credentials, due to Kyverno's cluster-wide high-privilege ServiceAccount, thereby compromising multi-tenant isolation.
Меры по смягчению последствий
Exploitation of this flaw requires the ability to create or modify Kyverno Policy, ClusterPolicy, or GlobalContextEntry resources. The primary mitigation is to remove policy-authoring permissions from untrusted and namespace-scoped users: restrict create, update, and patch on policies.kyverno.io, clusterpolicies.kyverno.io, and globalcontextentries.kyverno.io to cluster administrators, and audit any Role or ClusterRole that grants these verbs to tenant service accounts.
Дополнительная информация
Статус:
EPSS
7.7 High
CVSS3
Связанные уязвимости
Kyverno before 1.16.2 contains a server-side request forgery (SSRF) vulnerability in the APICall feature. The URL field in a Policy's ServiceCall configuration is not validated, so a user with namespace-level Policy creation permissions can direct Kyverno to make HTTP requests to arbitrary internal resources (e.g., cloud metadata endpoints such as 169.254.169.254 or other tenants' resources). Because Kyverno executes these requests using its cluster-wide high-privilege ServiceAccount (a Confused Deputy problem), the responses—potentially including other tenants' secrets and cloud IAM credentials—are returned in the PolicyReport and can be read by the attacker, breaking multi-tenant isolation.
Kyverno before 1.16.2 contains a server-side request forgery (SSRF) vulnerability in the APICall feature. The URL field in a Policy's ServiceCall configuration is not validated, so a user with namespace-level Policy creation permissions can direct Kyverno to make HTTP requests to arbitrary internal resources (e.g., cloud metadata endpoints such as 169.254.169.254 or other tenants' resources). Because Kyverno executes these requests using its cluster-wide high-privilege ServiceAccount (a Confused Deputy problem), the responses—potentially including other tenants' secrets and cloud IAM credentials—are returned in the PolicyReport and can be read by the attacker, breaking multi-tenant isolation.
EPSS
7.7 High
CVSS3