Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/kyverno/kyverno

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Kyverno versions prior to 1.19.1 have a namespace isolation bypass vulnerability in the apiCall context entry of namespaced Policy resources. This occurs due to inconsistent path interpretation between validation and execution, allowing a low-privilege tenant to use percent-encoded dot-segments in the urlPath to bypass namespace checks. Exploitation enables reading resources from other namespaces using the Kyverno admission controller's ServiceAccount credentials.

Join the discussion

Kyverno versions before 1.19.1 contain a critical vulnerability in the validation of URL-encoded path segments within the Policy apiCall urlPath. This flaw allows namespace tenants to bypass namespace restrictions and create objects in other namespaces using percent-encoded directory traversal sequences. Exploitation can lead to creation of MutatingWebhookConfiguration objects cluster-wide or PolicyException objects in the kyverno namespace, resulting in privilege escalation to cluster admin.

Join the discussion

Kyverno versions 1.16.0 through 1.19.0 have a vulnerability where the globalcontext.Lib CEL library is registered in the policy environment without namespace confinement. This allows a tenant with permission to create namespaced policies to access cached cluster-scoped global context entries, including data from namespaces they do not have RBAC permissions to read. The issue is fixed in version 1.19.1.

Join the discussion

Kyverno versions 1.14.0 through 1.19.0 contain a vulnerability in the ImageValidatingPolicy evaluator where it fails to properly read the spec.images and spec.allowedValues fields of a PolicyException. This causes image signature verification to be skipped for all images in a matched resource when an exception is intended only for specific images, allowing unsigned or untrusted images to be admitted without verification. The issue is resolved in version 1.19.1.

Join the discussion

Kyverno versions prior to 1.19.1 contain a server-side request forgery (SSRF) vulnerability. This issue arises because certain legacy API call paths do not enforce egress filtering or validate service URLs, allowing crafted policies or resource submitters to make Kyverno send HTTP requests to arbitrary internal or external hosts. The vulnerability can lead to unauthorized access to cloud metadata endpoints and internal services using Kyverno's network privileges. The flaw is fixed in version 1.19.1.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Package: pkg:github/kyverno/kyverno
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses