PT-2022-28078 · Kyverno · Kyverno

Slashben

·

Published

2022-12-21

·

Updated

2025-09-12

·

CVE-2022-47633

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kyverno versions 1.8.3 through 1.8.4
Description An image signature validation bypass issue allows a malicious image registry or a man-in-the-middle attacker to inject unsigned arbitrary container images into a protected Kubernetes cluster. This affects users of Kyverno who use verifyImages rules to verify container image signatures and do not prevent the use of unknown registries.
Recommendations For Kyverno versions 1.8.3 and 1.8.4, update to version 1.8.5 to resolve the issue. As a temporary workaround, consider configuring a Kyverno policy to restrict registries to a set of secure trusted image registries.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

BIT-KYVERNO-2022-47633
CVE-2022-47633
GHSA-M3CQ-XCX9-3GVM
GO-2022-1180

Affected Products

Kyverno