CVE-2022-47633
HIGHKyverno 1.8.3-1.8.4 - Image Signature Validation Bypass
Title source: llmDescription
An image signature validation bypass vulnerability in Kyverno 1.8.3 and 1.8.4 allows a malicious image registry (or a man-in-the-middle attacker) to inject unsigned arbitrary container images into a protected Kubernetes cluster. This is fixed in 1.8.5. This has been fixed in 1.8.5 and mitigations are available for impacted releases.
References (5)
Core 5
Core References
Patch, Third Party Advisory
https://github.com/kyverno/kyverno/compare/v1.8.4...v1.8.5
Patch, Third Party Advisory
https://github.com/kyverno/kyverno/pull/5713
Release Notes, Third Party Advisory
https://github.com/kyverno/kyverno/releases/tag/v1.8.5
Patch, Third Party Advisory
https://github.com/kyverno/kyverno/security/advisories/GHSA-m3cq-xcx9-3gvm
Scores
CVSS v3
8.1
EPSS
0.0096
EPSS Percentile
56.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-287
Status
published
Products (3)
kyverno/kyverno
1.8.3
kyverno/kyverno
1.8.4
kyverno/kyverno
1.8.3 - 1.8.5Go
Published
Dec 23, 2022
Tracked Since
Feb 18, 2026