Kyverno is a policy engine designed for Kubernetes. Kyverno seccomp control can be circumvented. Users of the podSecurity `validate.podSecurity` subrule in Kyverno 1.9.2 and 1.9.3 are vulnerable. This issue was patched in version 1.9.4.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://github.com/kyverno/kyverno/security/advisories/GHSA-33hq-f2mf-jm3c | vendor advisory |
https://github.com/kyverno/kyverno/pull/7263 | issue tracking |
https://github.com/kyverno/kyverno/releases/tag/v1.9.4 | release notes |