CyberRota Analysis
AI-GeneratedKubernetes deployments using Contrast versions 1.14.0 through 1.23.1 are vulnerable due to a flaw in runtime policy generation that allows unauthorized container image substitutions without proper image digest verification. This vulnerability can be exploited by an attacker with access to the Kata agent API, potentially allowing them to replace a container image with a malicious payload, thereby compromising the integrity of confidential containers. Organizations utilizing these versions of Contrast should prioritize remediation to protect against potential exploitation by insiders or compromised administrators.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Contrast (edgelesssys/contrast) versions 1.14.0 before 1.23.1 generate runtime policies that fail to detect all container image substitutions. A bad rebase during a Kata Containers update accidentally introduced an `allow_storage` rule that accepts storage entries using the `image_guest_pull` driver without verifying the image digest. An attacker with access to the Kata agent API — for example, a Kubernetes cluster administrator in Contrast's threat model — can therefore substitute a container image with an exploit payload, provided the substituted image satisfies the remaining policy rules, undermining the confidential container's integrity guarantees.