CyberRota Analysis
AI-GeneratedKyverno versions prior to 1.19.1 are vulnerable due to improper validation of URL-encoded path segments in the Policy apiCall urlPath, allowing namespace tenants to bypass restrictions and create objects in other namespaces. This vulnerability can be exploited using percent-encoded directory traversal sequences, potentially leading to privilege escalation to cluster admin through the creation of MutatingWebhookConfiguration objects or PolicyException objects. Organizations using Kyverno should prioritize patching to mitigate this critical risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Policy apiCall urlPath, allowing namespace tenants to bypass the per-namespace clamp and create objects in other namespaces as the admission-controller ServiceAccount. Attackers can exploit this by using percent-encoded directory traversal sequences to create MutatingWebhookConfiguration objects cluster-wide or PolicyException objects in the kyverno namespace, enabling privilege escalation to cluster admin.