Impact
The NeuVector admission webhook disregards containers whose image path matches one of three hardcoded service mesh sidecar images, ignoring them during policy evaluation. As a result, any workload author can craft a pod definition with an image path that mimics one of these sidecar images, enabling the container to bypass admission deny rules. This flaw allows unauthorized or malicious containers to be deployed without triggering the intended security checks, potentially exposing the cluster to policy violations and other risks associated with unaudited workloads. The weakness is classified as CWE‑807, indicating improper deferral of service functionality.
Affected Systems
SUSE’s deployment of the NeuVector admission webhook within Kubernetes clusters. Specific vendor: SUSE. Version details are not supplied, so any deployed instance running the unpatched codebase is vulnerable.
Risk and Exploitability
The CVSS score of 5.3 reflects a moderate severity, while the EPSS score of less than 1 % indicates a very low probability of exploitation at any given time. This vulnerability is not listed in the CISA KEV catalog. The attack vector can be inferred as remote via the Kubernetes API, since an attacker with deployment privileges can supply the image path. By submitting a pod manifest referencing one of the flagged sidecar images, the broker will silently exclude the container from policy enforcement, giving the attacker the same permissions as the deployer without any detectable policy violation.
OpenCVE Enrichment