PT-2025-12664 · Kyverno · Kyverno
Frgt10Cs
·
Published
2025-03-24
·
Updated
2025-09-12
·
CVE-2025-29778
CVSS v3.1
8.0
High
| Vector | AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Kyverno versions prior to 1.14.0-alpha.1
Description
Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to version 1.14.0-alpha.1, Kyverno ignores the
subjectRegExp and issuerRegExp fields when verifying artifact signatures in keyless mode. This allows an attacker to deploy Kubernetes resources with artifacts signed by an unexpected certificate. Deploying these unauthorized Kubernetes resources can lead to a full compromise of the Kubernetes cluster. The vulnerability occurs because Kyverno only checks the subject and issuer fields when verifying signatures, while the subjectRegExp and issuerRegExp fields, intended for more flexible matching, are not considered.Recommendations
Upgrade to Kyverno version 1.14.0-alpha.1 or later to resolve this issue.
Exploit
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kyverno