Image Signature Validation Bypass in Kyverno by nirmata
CVE-2022-47633
8.1HIGH
What is CVE-2022-47633?
A vulnerability in Kyverno versions 1.8.3 and 1.8.4 allows attackers, such as those operating a malicious image registry or acting as man-in-the-middle, to bypass image signature validation. This can lead to the injection of unsigned container images into protected Kubernetes clusters, risking the integrity and security of the deployed applications. The issue has been addressed in version 1.8.5, which includes necessary fixes and mitigations for the vulnerable versions.
