CVE-2024-48921 Information
Nov 01, 2024
cve
Description
Kyverno is a policy engine designed for Kubernetes. A kyverno ClusterPolicy ie. \disallow-privileged-containers\ can be overridden by the creation of a PolicyException in a random namespace. By design PolicyExceptions are consumed from any namespace. Administrators may not recognize that this allows users with privileges to non-kyverno namespaces to create exceptions. This vulnerability is fixed in 1.13.0.
Reference
https://github.com/kyverno/kyverno/security/advisories/GHSA-qjvc-p88j-j9rm
Share on: