PT-2022-28078 · Kyverno · Kyverno
Slashben
·
Published
2022-12-21
·
Updated
2025-09-12
·
CVE-2022-47633
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Kyverno versions 1.8.3 through 1.8.4
Description
An image signature validation bypass issue allows a malicious image registry or a man-in-the-middle attacker to inject unsigned arbitrary container images into a protected Kubernetes cluster. This affects users of Kyverno who use
verifyImages rules to verify container image signatures and do not prevent the use of unknown registries.Recommendations
For Kyverno versions 1.8.3 and 1.8.4, update to version 1.8.5 to resolve the issue.
As a temporary workaround, consider configuring a Kyverno policy to restrict registries to a set of secure trusted image registries.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kyverno