CVE Database
/

CVE-2024-48921

Back to search

CVE-2024-48921

Published: Oct 29, 2024

Modified: Oct 29, 2024

PUBLISHED

Description

Kyverno is a policy engine designed for Kubernetes. A kyverno ClusterPolicy, ie. "disallow-privileged-containers," can be overridden by the creation of a PolicyException in a random namespace. By design, PolicyExceptions are consumed from any namespace. Administrators may not recognize that this allows users with privileges to non-kyverno namespaces to create exceptions. This vulnerability is fixed in 1.13.0.

VendorProductVersions

kyverno

kyverno

affected
< 1.13.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2024-48921 - Security Vulnerability | QwikSec