CVE-2023-33191

kyverno seccomp control can be circumvented in go/github.com/kyverno/kyverno

Identifiers

GHSA-33hq-f2mf-jm3c, CVE-2023-33191

Package Slug

go/github.com/kyverno/kyverno

Vulnerability

kyverno seccomp control can be circumvented

Description

Impact

Users of the podSecurity (validate.podSecurity) subrule in Kyverno 1.9. See the documentation for information on this subrule type. Users of Kyverno v1.9.2 and v1.9.3 are affected.

Patches

v1.9.4 v1.10.0

Workarounds

To work around this issue without upgrading to v1.9.4, temporarily install individual policies for the respective Seccomp checks in baseline here and restricted here.

References

  • https://kyverno.io/docs/writing-policies/validate/#pod-security
  • https://github.com/kyverno/kyverno/pull/7263
Affected Versions

All versions starting from 1.9.2 before 1.9.4

Solution

Upgrade to version 1.9.4 or above.

Last Modified

2023-05-26

source