QID 995931
Date Published: 2023-11-16
QID 995931: GO (Go) Security Update for github.com/kyverno/kyverno (GHSA-3hfq-cx9j-923w)
An issue was found in Kyverno that allowed an attacker to control the digest of images used by Kyverno users. The issue would require the attacker to compromise the registry that the Kyverno fetch their images from. The attacker could then return a vulnerable image to the the user and leverage that to further escalate their position. As such, the attacker would need to know which images the Kyverno user consumes and know of one of multiple exploitable vulnerabilities in previous digests of the images. Alternatively, if the attacker has compromised the registry, they could craft a malicious image with a different digest with intentionally placed vulnerabilities and deliver the image to the user.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
- GHSA-3hfq-cx9j-923w -
github.com/advisories/GHSA-3hfq-cx9j-923w
CVEs related to QID 995931
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-3hfq-cx9j-923w | github.com/kyverno/kyverno |
|