Kyverno 是 Kubernetes 的策略引擎。在 1.14.0 到 1.19.0 版本中,ImageValidatingPolicy(policies.kyverno.io/v1beta1)评估器不会读取 PolicyException 的 spec.images 和 spec.allowedValues 字段。任何其 policyRefs 和 matchConditions 与某个资源匹配的 PolicyException 都会导致整个资源跳过镜像签名验证,而不是仅对列出的镜像或值跳过。因此,本意是豁免单
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100706 | 9.9 CRITICAL | kyverno before 1.19.1 Privilege Escalation via Policy apiCall urlPath |
| CVE-2026-100707 | 7.7 HIGH | Kyverno before 1.19.1 Namespace Isolation Bypass via Percent-Encoded Path |
| CVE-2026-100703 | 7.7 HIGH | Kyverno before 1.19.1 Cross-Namespace Data Access via globalcontext.Lib |
| CVE-2026-100705 | 7.6 HIGH | Kyverno before 1.19.1 SSRF via legacy apiCall service executor |
No comments yet