CVE-2022-47633: High severity kyverno vulnerability
Impact
Users of Kyverno on versions 1.8.3 or 1.8.4 who use verifyImages rules to verify container image signatures, and do not prevent use of unknown registries.
Patches
This issue has been fixed in version 1.8.5
Workarounds
Configure a Kyverno policy to restrict registries to a set of secure trusted image registries (sample).
References
Other sources
An image signature validation bypass vulnerability in Kyverno 1.8.3 and 1.8.4 allows a malicious image registry (or a man-in-the-middle attacker) to inject unsigned arbitrary container images into a protected Kubernetes cluster. This is fixed in 1.8.5. This has been fixed in 1.8.5 and mitigations are available for impacted releases.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this Kyverno security issue?
The vulnerability ID for this Kyverno security issue is CVE-2022-47633.
What is the impact of this vulnerability?
The impact of this vulnerability is that it allows a malicious image to bypass signature validation in Kyverno 1.8.3 and 1.8.4.
What versions of Kyverno are affected by this vulnerability?
Versions 1.8.3 and 1.8.4 of Kyverno are affected by this vulnerability.
How can I fix this vulnerability?
To fix this vulnerability, update to version 1.8.5 of Kyverno.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability in the Kyverno security advisories, pull request, and release notes.