HIGH 8.1 Go
kyverno verifyImages rule bypass possible with malicious proxy/registry
GHSA-m3cq-xcx9-3gvm · BIT-kyverno-2022-47633 · CVE-2022-47633 · GO-2022-1180
Published · Modified
Description
Impact
Users of Kyverno on versions 1.8.3 or 1.8.4 who use verifyImages rules to verify container image signatures, and do not prevent use of unknown registries.
Patches
This issue has been fixed in version 1.8.5
Workarounds
Configure a Kyverno policy to restrict registries to a set of secure trusted image registries (sample).
References
References
- WEB https://github.com/kyverno/kyverno/security/advisories/GHSA-m3cq-xcx9-3gvm
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2022-47633
- WEB https://github.com/kyverno/kyverno/pull/5713
- PACKAGE https://github.com/kyverno/kyverno
- WEB https://github.com/kyverno/kyverno/compare/v1.8.4...v1.8.5
- WEB https://github.com/kyverno/kyverno/releases/tag/v1.8.5
- WEB https://kyverno.io/docs/writing-policies/verify-images
- WEB https://kyverno.io/policies/best-practices/restrict_image_registries/restrict_image_registries
- WEB https://pkg.go.dev/vuln/GO-2022-1180
- WEB https://web.archive.org/web/20230426095744/https://kyverno.io/policies/best-practices/restrict_image_registries/restrict_image_registries
Ready to move
Start Securing
Free, no credit card | First findings in minutes