Affected by GO-2023-1801
and 17 other vulnerabilities
GO-2023-1801 : kyverno seccomp control can be circumvented in github.com/kyverno/kyverno
GO-2023-1804 : Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
GO-2023-1819 : Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
GO-2023-2340 : Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
GO-2024-3230 : Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
GO-2025-3562 : Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
GO-2025-3615 : Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
GO-2025-3652 : Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
GO-2025-3823 : Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
GO-2026-4285 : Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
GO-2026-4381 : Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
GO-2026-4382 : Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
GO-2026-5268 : Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
GO-2026-5337 : Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
GO-2026-5351 : Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
GO-2026-5371 : Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
GO-2026-5575 : kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
GO-2026-5594 : Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Discover Packages
github.com/kyverno/kyverno
pkg
testrunner
package
Version:
v1.9.3
Opens a new window with list of versions in this module.
Published: May 9, 2023
License: Apache-2.0
Opens a new window with license information.
Imports: 22
Opens a new window with list of imports.
Imported by: 0
Opens a new window with list of known importers.
Documentation
Documentation
¶
ConvertToUnstructured converts a resource to unstructured format
LoadFile loads file in byte buffer
RootDir returns the kyverno project directory based on the location of the current file.
It assumes that the project directory is 2 levels up. This means if this function is moved
it may not work as expected.
type Expected struct {
Mutation Mutation `yaml:"mutation,omitempty"`
Validation Validation `yaml:"validation,omitempty"`
Generation Generation `yaml:"generation,omitempty"`
}
type Input struct {
Policy string `yaml:"policy"`
Resource string `yaml:"resource"`
LoadResources []string `yaml:"loadresources,omitempty"`
}
Input defines input for a test scenario
type Mutation struct {
PatchedResource string `yaml:"patchedresource,omitempty"`
PolicyResponse response .PolicyResponse `yaml:"policyresponse"`
}
type Scenario struct {
TestCases []TestCase
}
type TestCase struct {
Input Input `yaml:"input"`
Expected Expected `yaml:"expected"`
}
TestCase defines input and output for a case
Source Files
¶
Click to show internal directories.
Click to hide internal directories.