PT-2026-84144 · Kyverno · Kyverno
CVE-2023-54356
·
Published
2023-05-30
·
Updated
2026-09-01
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Kyverno versions prior to 1.9.5
Description
TLS endpoints support insecure 3DES cipher suites, specifically TLS ECDHE RSA WITH 3DES EDE CBC SHA and TLS RSA WITH 3DES EDE CBC SHA. These 64-bit block ciphers are susceptible to the Sweet32 attack, where an attacker could recover small amounts of plaintext over very long-lived TLS connections that carry large volumes of traffic.
Recommendations
Update to version 1.9.5 or 1.10.0.
Exploit
Fix
Inadequate Encryption Strength
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kyverno