Impact
IBM Portieris 0.5.0 through 0.14.2 contains an authorization flaw that allows a remote authenticated attacker to bypass image policy enforcement by exploiting unvalidated pod owner references. The flaw permits the attacker to override the intended security controls governing which container images are allowed to run, potentially enabling the deployment of malicious or compromised images and undermining the integrity of the Kubernetes cluster.
Affected Systems
All instances of IBM Portieris versions 0.5.0 through 0.14.2 are affected. The fix is released in version 0.14.3 and can be downloaded from the IBM Portieris GitHub release page.
Risk and Exploitability
The vulnerability has a CVSS score of 8.1, indicating high severity. EPSS data is not available, and the issue is not listed in CISA’s KEV catalog, but the CVSS score and noted exploitation path suggest a high likelihood that a privileged, authenticated attacker could exploit the weakness. The attack vector is remote, requiring authenticated access to the Portieris service.
OpenCVE Enrichment