blob: fe39573410d60bab6258422dc0d3e52e92e511df [file] [log] [blame]
modules:
- module: github.com/kyverno/kyverno
versions:
- introduced: 1.8.3
fixed: 1.8.5
vulnerable_at: 1.8.4
packages:
- package: github.com/kyverno/kyverno/pkg/engine
symbols:
- imageVerifier.verifyAttestation
- imageVerifier.verifyAttestations
- imageVerifier.verifyAttestors
- imageVerifier.verifyAttestorSet
- imageVerifier.verifyImage
description: |
`verifyImages` rules can be bypassed by a malicious proxy/registry.
cves:
- CVE-2022-47633
ghsas:
- GHSA-m3cq-xcx9-3gvm
credit: '@slashben'
references:
- advisory: https://github.com/kyverno/kyverno/security/advisories/GHSA-m3cq-xcx9-3gvm
- fix: https://github.com/kyverno/kyverno/pull/5713
- web: https://kyverno.io/policies/best-practices/restrict_image_registries/restrict_image_registries