Kyverno

Kyverno

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.05%
  • Veröffentlicht 27.01.2026 16:10:44
  • Zuletzt bearbeitet 02.02.2026 15:20:13

Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 have unbounded memory consumption in Kyverno's policy engine that allows users with policy creation privileges to cause denial of ser...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 27.01.2026 16:07:19
  • Zuletzt bearbeitet 02.02.2026 15:13:57

Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 have a critical authorization boundary bypass in namespaced Kyverno Policy apiCall. The resolved `urlPath` is executed using the Kyve...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 23.07.2025 20:35:21
  • Zuletzt bearbeitet 05.08.2025 15:51:19

Kyverno is a policy engine designed for cloud native platform engineering teams. In versions 1.14.1 and below, a Denial of Service (DoS) vulnerability exists due to improper handling of JMESPath variable substitutions. Attackers with permissions to c...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 30.04.2025 14:55:13
  • Zuletzt bearbeitet 16.05.2025 16:42:35

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.13.5 and 1.14.0, it may happen that policy rules using namespace selector(s) in their match statements are mistakenly not applied during admission re...

Exploit
  • EPSS 0.11%
  • Veröffentlicht 24.03.2025 16:38:08
  • Zuletzt bearbeitet 01.08.2025 13:10:56

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to version 1.14.0-alpha.1, Kyverno ignores subjectRegExp and IssuerRegExp while verifying artifact's sign with keyless mode. It allows the attacker to deploy kuber...

  • EPSS 0.56%
  • Veröffentlicht 14.11.2023 21:15:13
  • Zuletzt bearbeitet 21.11.2024 08:30:34

Kyverno is a policy engine designed for Kubernetes. An issue was found in Kyverno that allowed an attacker to control the digest of images used by Kyverno users. The issue would require the attacker to compromise the registry that the Kyverno users f...

  • EPSS 0.18%
  • Veröffentlicht 23.12.2022 23:15:08
  • Zuletzt bearbeitet 15.04.2025 04:15:33

An image signature validation bypass vulnerability in Kyverno 1.8.3 and 1.8.4 allows a malicious image registry (or a man-in-the-middle attacker) to inject unsigned arbitrary container images into a protected Kubernetes cluster. This is fixed in 1.8....