Vulnerability Report: GO-2022-1180

A malicious proxy/registry can bypass verifyImages rules.

For detailed information about this vulnerability, visit https://github.com/kyverno/kyverno/security/advisories/GHSA-m3cq-xcx9-3gvm.

Affected Packages

  • Path
    Go Versions
    Symbols
  • from v1.8.3 before v1.8.5
    5 unexported affected symbols
    • imageVerifier.verifyAttestation
    • imageVerifier.verifyAttestations
    • imageVerifier.verifyAttestorSet
    • imageVerifier.verifyAttestors
    • imageVerifier.verifyImage

Aliases

References

Credits

  • @slashben

Feedback

See anything missing or incorrect? Suggest an edit to this report.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL