Attacker can cause Kyverno user to unintentionally consume insecure image
CVE-2023-47630
7.1HIGH
What is CVE-2023-47630?
A vulnerability in Kyverno, a policy engine for Kubernetes, allows an attacker to manipulate the image digest used by Kyverno users. This requires the attacker to gain access to the image registry that the users are fetching their images from, enabling the delivery of a compromised image. Users who pull images by digests from trusted registries remain unaffected. The issue has been resolved in version 1.10.5, and users are strongly encouraged to upgrade. No workarounds are available.
Affected Version(s)
kyverno < 1.10.5
