Affected by GO-2023-1819
and 15 other vulnerabilities
GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
package
Version:
v1.10.0-alpha.1
Opens a new window with list of versions in this module.
Published: Apr 6, 2023
License: Apache-2.0
Opens a new window with license information.
Imports: 6
Opens a new window with list of imports.
Imported by: 0
Opens a new window with list of known importers.
Documentation
¶
View Source
const (
PolicyAnnotation = "policies.kyverno.io/last-applied-patches"
ManagedByLabel = "webhook.kyverno.io/managed-by"
KyvernoComponentLabel = "app.kubernetes.io/component"
)
View Source
var OperationToPastTense = map[string]string{
"add": "added",
"remove": "removed",
"replace": "replaced",
"move": "moved",
"copy": "copied",
"test": "tested",
}
type RulePatch struct {
RuleName string `json:"rulename"`
Op string `json:"op"`
Path string `json:"path"`
}
Source Files
¶
Directories
¶
Click to show internal directories.
Click to hide internal directories.