PT-2026-99374 · Kyverno · Kyverno
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Kyverno versions 1.16.0 through 1.19.0
Description
The software registers the
globalcontext.Lib Common Expression Language (CEL) library in its policy environment without restricting it to the policy's namespace. This differs from other libraries like resource.Lib, http.Lib, and the configMap loader, which are confined to the policy namespace. A tenant with permissions to create namespaced policies, such as NamespacedValidatingPolicy or similar mutating, deleting, generating, and image-validating policies, can use the globalContext.get() function to retrieve the full cached contents of a cluster-scoped GlobalContextEntry. This allows access to data cached from namespaces for which the tenant lacks RBAC (Role-Based Access Control) permissions, as no admission validation prevents these calls.Recommendations
Update Kyverno to version 1.19.1.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kyverno