Impact
Kyverno versions earlier than 1.9.5 enable the 3DES cipher suites TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA and TLS_RSA_WITH_3DES_EDE_CBC_SHA, which have 64‑bit block sizes. These ciphers make the service vulnerable to the Sweet32 attack, allowing a passive eavesdropper to recover small amounts of plaintext from long‑lived TLS connections that carry large volumes of traffic. The consequence is a confidentiality breach that can expose sensitive application data when the attack conditions are met.
Affected Systems
The vulnerability affects Kyverno deployments running version 1.9.4 and earlier. The issue is resolved in Kyverno 1.9.5 and later releases such as 1.10.0.
Risk and Exploitability
The CVSS score of 9.3 classifies this weakness as high severity. The EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog, indicating no publicly known exploits at this time. The likely attack vector is a remote TLS session intercepted by an attacker, which would need to exercise long‑duration traffic to collect enough ciphertext blocks for decryption. While the theoretical risk is high, the practical exploitation requires specific conditions, placing it in a moderate exploitation likelihood category.
OpenCVE Enrichment