CVE-2022-47633: High severity kyverno vulnerability

Published Dec 21, 2022
·
Updated

Impact

Users of Kyverno on versions 1.8.3 or 1.8.4 who use verifyImages rules to verify container image signatures, and do not prevent use of unknown registries.

Patches

This issue has been fixed in version 1.8.5

Workarounds

Configure a Kyverno policy to restrict registries to a set of secure trusted image registries (sample).

References

Other sources

An image signature validation bypass vulnerability in Kyverno 1.8.3 and 1.8.4 allows a malicious image registry (or a man-in-the-middle attacker) to inject unsigned arbitrary container images into a protected Kubernetes cluster. This is fixed in 1.8.5. This has been fixed in 1.8.5 and mitigations are available for impacted releases.

Affected Software

3 affected componentsFixes available
Kyverno Kyverno=1.8.3
Kyverno Kyverno=1.8.4
go/github.com/kyverno/kyverno>=1.8.3<1.8.5
1.8.5

Event History

Dec 21, 2022
Advisory Published
via GitHub·05:24 PM
Dec 23, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·11:15 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the vulnerability ID for this Kyverno security issue?

The vulnerability ID for this Kyverno security issue is CVE-2022-47633.

2

What is the impact of this vulnerability?

The impact of this vulnerability is that it allows a malicious image to bypass signature validation in Kyverno 1.8.3 and 1.8.4.

3

What versions of Kyverno are affected by this vulnerability?

Versions 1.8.3 and 1.8.4 of Kyverno are affected by this vulnerability.

4

How can I fix this vulnerability?

To fix this vulnerability, update to version 1.8.5 of Kyverno.

5

Where can I find more information about this vulnerability?

You can find more information about this vulnerability in the Kyverno security advisories, pull request, and release notes.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203