kyverno verifyImages rule bypass possible with malicious proxy/registry
Package
Affected versions
>= 1.8.3, < 1.8.5
Patched versions
1.8.5
Description
Published to the GitHub Advisory Database
Dec 21, 2022
Reviewed
Dec 21, 2022
Published by the National Vulnerability Database
Dec 23, 2022
Last updated
Jan 23, 2024
Impact
Users of Kyverno on versions 1.8.3 or 1.8.4 who use
verifyImages
rules to verify container image signatures, and do not prevent use of unknown registries.Patches
This issue has been fixed in version 1.8.5
Workarounds
Configure a Kyverno policy to restrict registries to a set of secure trusted image registries (sample).
References
References