Kyverno 1.16.4 之前的版本在 服务模式下的出站 HTTP 请求中,会自动附加准入控制器(admission controller)的 ServiceAccount 令牌,且未携带显式的授权头。攻击者可以通过将 请求指向外部或攻击者控制的端点,从而窃取该令牌,进而获得对 Kyverno 策略及集群资源的完全控制权。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84200 | 9.0 CRITICAL | Kyverno before v1.13.0 Policy Bypass via Multiple Exceptions |
| CVE-2026-84199 | 7.7 HIGH | Kyverno before 1.16.2 SSRF via APICall Feature |
| CVE-2026-84196 | 7.7 HIGH | Kyverno before 1.18.0 Server-Side Request Forgery via apiCall |
| CVE-2025-15613 | 6.5 MEDIUM | Kyverno before v1.13.4 SSRF via Service Call |
| CVE-2023-54356 | 3.7 LOW | Kyverno before 1.9.5 Sweet32 Medium Strength Cipher Suites |
No comments yet