Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to version 1.14.0-alpha.1, Kyverno ignores subjectRegExp and IssuerRegExp while verifying artifact's sign with keyless mode. It allows the attacker to deploy kubernetes resources with the artifacts that were signed by unexpected certificate. Deploying these unauthorized kubernetes resources can lead to full compromise of kubernetes cluster. Version 1.14.0-alpha.1 contains a patch for the issue.
Metrics
Affected Vendors & Products
References
History
Mon, 24 Mar 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 24 Mar 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to version 1.14.0-alpha.1, Kyverno ignores subjectRegExp and IssuerRegExp while verifying artifact's sign with keyless mode. It allows the attacker to deploy kubernetes resources with the artifacts that were signed by unexpected certificate. Deploying these unauthorized kubernetes resources can lead to full compromise of kubernetes cluster. Version 1.14.0-alpha.1 contains a patch for the issue. | |
Title | Kyverno ignores subjectRegExp and IssuerRegExp | |
Weaknesses | CWE-285 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-03-24T16:38:08.104Z
Updated: 2025-03-24T17:55:28.379Z
Reserved: 2025-03-11T14:23:00.475Z
Link: CVE-2025-29778

Updated: 2025-03-24T17:55:24.257Z

Status : Received
Published: 2025-03-24T17:15:20.970
Modified: 2025-03-24T17:15:20.970
Link: CVE-2025-29778

No data.