Affected by GO-2023-1804
and 15 other vulnerabilities
GO-2023-1804 : Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
GO-2023-1819 : Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
GO-2023-2340 : Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
GO-2024-3230 : Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
GO-2025-3562 : Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
GO-2025-3615 : Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
GO-2025-3652 : Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
GO-2025-3823 : Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
GO-2026-4381 : Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
GO-2026-4382 : Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
GO-2026-5268 : Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
GO-2026-5337 : Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
GO-2026-5351 : Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
GO-2026-5371 : Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
GO-2026-5575 : kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
GO-2026-5594 : Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Discover Packages
github.com/kyverno/kyverno
pkg
engine
utils
package
Version:
v1.5.2
Opens a new window with list of versions in this module.
Published: Dec 10, 2021
License: Apache-2.0
Opens a new window with license information.
Imports: 7
Opens a new window with list of imports.
Imported by: 1
Opens a new window with list of known importers.
Documentation
Documentation
¶
ApplyPatchNew patches given resource with given joined patches
ApplyPatches patches given resource with given patches and returns patched document
return original resource if any error occurs
ConvertToUnstructured converts the resource to unstructured format
func GetAnchorsFromMap(anchorsMap map[string ]interface{}) map[string ]interface{}
GetAnchorsFromMap gets the conditional anchor map
func JoinPatches(patches [][]byte ) []byte
JoinPatches joins array of serialized JSON patches to the single JSONPatch array
RuleType defines the type for rule
const (
Mutation RuleType = iota
Validation
Generation
ImageVerify
)
Source Files
¶
Click to show internal directories.
Click to hide internal directories.