PT-2026-84144 · Kyverno · Kyverno

CVE-2023-54356

·

Published

2023-05-30

·

Updated

2026-09-01

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Kyverno versions prior to 1.9.5
Description TLS endpoints support insecure 3DES cipher suites, specifically TLS ECDHE RSA WITH 3DES EDE CBC SHA and TLS RSA WITH 3DES EDE CBC SHA. These 64-bit block ciphers are susceptible to the Sweet32 attack, where an attacker could recover small amounts of plaintext over very long-lived TLS connections that carry large volumes of traffic.
Recommendations Update to version 1.9.5 or 1.10.0.

Exploit

Fix

Inadequate Encryption Strength

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-54356
GHSA-HGV6-W7R3-W4QW
GO-2023-1804

Affected Products

Kyverno