CVE-2023-34091: Kyverno resource with a deletionTimestamp may allow policy circumvention

Published Jun 1, 2023
·
Updated

Kyverno is a policy engine designed for Kubernetes. In versions of Kyverno prior to 1.10.0, resources which have the deletionTimestamp field defined can bypass validate, generate, or mutate-existing policies, even in cases where the validationFailureAction field is set to Enforce. This situation occurs as resources pending deletion were being consciously exempted by Kyverno, as a way to reduce processing load as policies are typically not applied to objects which are being deleted. However, this could potentially result in allowing a malicious user to leverage the Kubernetes finalizers feature by setting a finalizer which causes the Kubernetes API server to set the deletionTimestamp and then not completing the delete operation as a way to explicitly to bypass a Kyverno policy. Note that this is not applicable to Kubernetes Pods but, as an example, a Kubernetes Service resource can be manipulated using an indefinite finalizer to bypass policies. This is resolved in Kyverno 1.10.0. There is no known workaround.

Affected Software

1 affected component
Nirmata Kyverno Go<1.10.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 1.10.0

Event History

Jun 1, 2023
CVE Published
via MITRE·04:24 PM
Data Sourced
via MITRE·04:24 PM
DescriptionSeverityWeakness
Data Sourced
05:15 PM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is CVE-2023-34091?

CVE-2023-34091 is a vulnerability in Kyverno, a policy engine designed for Kubernetes, that allows resources with the 'deletionTimestamp' field defined to bypass certain policies.

2

How does CVE-2023-34091 affect Kyverno?

In versions prior to 1.10.0, Kyverno allows resources with the 'deletionTimestamp' field defined to bypass validate, generate, or mutate-existing policies, even when the 'validationFailureAction' field is set to 'Enforce'.

3

What is the severity of CVE-2023-34091?

CVE-2023-34091 has a severity rating of medium (6.5) based on the CVSSv3 scoring system.

4

How can I fix CVE-2023-34091?

To fix CVE-2023-34091, users should update Kyverno to version 1.10.0 or higher.

5

Is there any additional information available on CVE-2023-34091?

Yes, you can find more information in the release notes for Kyverno version 1.10.0 and the security advisory on GitHub.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203