You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
kyverno verifyImages rule bypass possible with malicious proxy/registry
High severity
GitHub Reviewed
Published
Dec 21, 2022
in
kyverno/kyverno
•
Updated Jan 23, 2024
Users of Kyverno on versions 1.8.3 or 1.8.4 who use verifyImages rules to verify container image signatures, and do not prevent use of unknown registries.
Impact
Users of Kyverno on versions 1.8.3 or 1.8.4 who use
verifyImages
rules to verify container image signatures, and do not prevent use of unknown registries.Patches
This issue has been fixed in version 1.8.5
Workarounds
Configure a Kyverno policy to restrict registries to a set of secure trusted image registries (sample).
References
References