Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3117 | Kyverno is a policy engine designed for Kubernetes. A kyverno ClusterPolicy, ie. "disallow-privileged-containers," can be overridden by the creation of a PolicyException in a random namespace. By design, PolicyExceptions are consumed from any namespace. Administrators may not recognize that this allows users with privileges to non-kyverno namespaces to create exceptions. This vulnerability is fixed in 1.13.0. |
Github GHSA |
GHSA-qjvc-p88j-j9rm | Kyverno's PolicyException objects can be created in any namespace by default |
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 07 Nov 2024 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nirmata
Nirmata kyverno |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:nirmata:kyverno:*:*:*:*:*:go:*:* | |
| Vendors & Products |
Nirmata
Nirmata kyverno |
|
| Metrics |
cvssV3_1
|
Tue, 29 Oct 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kyverno
Kyverno kyverno |
|
| CPEs | cpe:2.3:a:kyverno:kyverno:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Kyverno
Kyverno kyverno |
|
| Metrics |
ssvc
|
Tue, 29 Oct 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kyverno is a policy engine designed for Kubernetes. A kyverno ClusterPolicy, ie. "disallow-privileged-containers," can be overridden by the creation of a PolicyException in a random namespace. By design, PolicyExceptions are consumed from any namespace. Administrators may not recognize that this allows users with privileges to non-kyverno namespaces to create exceptions. This vulnerability is fixed in 1.13.0. | |
| Title | Kyverno's PolicyException objects can be created in any namespace by default | |
| Weaknesses | CWE-285 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-10-29T14:58:36.597Z
Reserved: 2024-10-09T22:06:46.173Z
Link: CVE-2024-48921
Updated: 2024-10-29T14:58:29.297Z
Status : Analyzed
Published: 2024-10-29T15:15:10.593
Modified: 2024-11-07T17:20:34.160
Link: CVE-2024-48921
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA