Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40933
HistoryJun 16, 2023 - 7:19 p.m.

Policy Bypass

2023-06-1619:19:50
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5
kyverno
policy bypass
vulnerability
kubernetes
api server

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

EPSS

0.001

Percentile

17.6%

github.com/kyverno/kyverno is vulnerable to Policy Bypass. The vulnerability exists due to the deletionTimestamp field which by design bypasses policies. An attacker can utilize the Kubernetes finalizers feature by setting a finalizer which causes the Kubernetes API server to set the deletionTimestamp, resulting in policy bypass.

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

EPSS

0.001

Percentile

17.6%

Related for VERACODE:40933