8.8
CVE-2023-33191
- EPSS 0.49%
- Veröffentlicht 30.05.2023 07:15:09
- Zuletzt bearbeitet 21.11.2024 08:05:05
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
kyverno seccomp control can be circumvented
Kyverno is a policy engine designed for Kubernetes. Kyverno seccomp control can be circumvented. Users of the podSecurity `validate.podSecurity` subrule in Kyverno 1.9.2 and 1.9.3 are vulnerable. This issue was patched in version 1.9.4.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.49% | 0.379 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| security-advisories@github.com | 4.6 | 1.2 | 3.4 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
https://github.com/kyverno/kyverno/pull/7263
https://github.com/kyverno/kyverno/releases/tag/v1.9.4
https://github.com/kyverno/kyverno/security/advisories/GHSA-33hq-f2mf-jm3c