CyberRota Analysis
AI-GeneratedKyverno versions 1.16.0 to 1.19.0 are vulnerable due to improper confinement of the globalcontext.Lib CEL library, allowing tenants to access sensitive data from cluster-scoped GlobalContextEntries without appropriate RBAC permissions. This vulnerability could lead to unauthorized information disclosure, impacting the security of the Kubernetes environment. Organizations using affected versions of Kyverno should prioritize upgrading to version 1.19.1 or later to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Kyverno 1.16.0 through 1.19.0 registers the globalcontext.Lib CEL library in its policy environment without confining it to the policy's namespace, unlike the sibling libraries (resource.Lib, http.Lib, configMap loader) which are handed the policy namespace. A tenant who can create a namespaced policy (e.g. NamespacedValidatingPolicy, and likewise the namespaced mutating, deleting, generating, and image-validating policy kinds) in their own namespace can call globalContext.get("<entry>", "") and receive the full cached contents of a cluster-scoped GlobalContextEntry, including data cached from namespaces the tenant has no RBAC permission to read. No admission validation rejects such calls. Fixed in 1.19.1.