Image Signature Validation Bypass in Kyverno by nirmata
CVE-2022-47633

8.1HIGH

Key Information:

Vendor

Kyverno

Status
Vendor
CVE Published:
23 December 2022

What is CVE-2022-47633?

A vulnerability in Kyverno versions 1.8.3 and 1.8.4 allows attackers, such as those operating a malicious image registry or acting as man-in-the-middle, to bypass image signature validation. This can lead to the injection of unsigned container images into protected Kubernetes clusters, risking the integrity and security of the deployed applications. The issue has been addressed in version 1.8.5, which includes necessary fixes and mitigations for the vulnerable versions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.