Kyverno is a policy engine designed for Kubernetes. A kyverno ClusterPolicy, ie. "disallow-privileged-containers," can be overridden by the creation of a PolicyException in a random namespace. By design, PolicyExceptions are consumed from any namespace. Administrators may not recognize that this allows users with privileges to non-kyverno namespaces to create exceptions. This vulnerability is fixed in 1.13.0.
History

Thu, 07 Nov 2024 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Nirmata
Nirmata kyverno
Weaknesses CWE-863
CPEs cpe:2.3:a:nirmata:kyverno:*:*:*:*:*:go:*:*
Vendors & Products Nirmata
Nirmata kyverno
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'}


Tue, 29 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Kyverno
Kyverno kyverno
CPEs cpe:2.3:a:kyverno:kyverno:*:*:*:*:*:*:*:*
Vendors & Products Kyverno
Kyverno kyverno
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Oct 2024 14:30:00 +0000

Type Values Removed Values Added
Description Kyverno is a policy engine designed for Kubernetes. A kyverno ClusterPolicy, ie. "disallow-privileged-containers," can be overridden by the creation of a PolicyException in a random namespace. By design, PolicyExceptions are consumed from any namespace. Administrators may not recognize that this allows users with privileges to non-kyverno namespaces to create exceptions. This vulnerability is fixed in 1.13.0.
Title Kyverno's PolicyException objects can be created in any namespace by default
Weaknesses CWE-285
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-10-29T14:14:36.260Z

Updated: 2024-10-29T14:58:36.597Z

Reserved: 2024-10-09T22:06:46.173Z

Link: CVE-2024-48921

cve-icon Vulnrichment

Updated: 2024-10-29T14:58:29.297Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-29T15:15:10.593

Modified: 2024-11-07T17:20:34.160

Link: CVE-2024-48921

cve-icon Redhat

No data.