Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2023-54356— Kyverno before 1.9.5 Sweet32 Medium Strength Cipher Suites

Quick assessment

Affected
kyverno kyverno
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Kyverno 1.9.4 及更早版本在其 TLS 端点上支持不安全的 3DES 加密套件(TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA 和 TLS_RSA_WITH_3DES_EDE_CBC_SHA)。这些 64 位分组密码易受 Sweet32 攻击(CVE-2016-2183)的影响。在承载大量数据的长期 TLS 连接中,攻击者可能借此恢复少量明文数据。该问题已在 Kyverno 1.9.5 和 1.10.0 版本中修复。

CVSS 3.7 · Low

Possible ATT&CK Techniques 1 AI

T1528 · Steal Application Access Token
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2023-54356

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Kyverno before 1.9.5 Sweet32 Medium Strength Cipher Suites
Source: CVE Program / CVE List V5
Vulnerability Description
Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites (TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA and TLS_RSA_WITH_3DES_EDE_CBC_SHA) on their TLS endpoints. These 64-bit block ciphers are vulnerable to the Sweet32 attack (CVE-2016-2183), which, over very long-lived TLS connections carrying large volumes of traffic, could allow an attacker to recover small amounts of plaintext. The issue is fixed in Kyverno 1.9.5 and 1.10.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
不充分的加密强度
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
kyverno kyverno 0 ~ 1.9.5, 1.10.0 -

II. Public POCs for CVE-2023-54356

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-54356

登录查看更多情报信息。

Other References for CVE-2023-54356 (2)

Same Patch Batch · kyverno · 2026-09-01 · 6 CVEs total

CVE-2026-84200 9.0 CRITICAL Kyverno before v1.13.0 Policy Bypass via Multiple Exceptions
CVE-2026-84199 7.7 HIGH Kyverno before 1.16.2 SSRF via APICall Feature
CVE-2026-84195 7.7 HIGH Kyverno before 1.16.4 Credential Leak via apiCall
CVE-2026-84196 7.7 HIGH Kyverno before 1.18.0 Server-Side Request Forgery via apiCall
CVE-2025-15613 6.5 MEDIUM Kyverno before v1.13.4 SSRF via Service Call

IV. Related Vulnerabilities

V. Comments for CVE-2023-54356

No comments yet


Leave a comment