Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements
Published Apr 30, 2025
8.6
HIGHCVSS 3.1
EPSS 0.75%
Description
Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.13.5 and 1.14.0, it may happen that policy rules using namespace selector(s) in their match statements are mistakenly not applied during admission review request processing due to a missing error propagation in function `GetNamespaceSelectorsFromNamespaceLister` in `pkg/utils/engine/labels.go`. As a consequence, security-critical mutations and validations are bypassed, potentially allowing attackers with K8s API access to perform malicious operations. This issue has been patched in versions 1.13.5 and 1.14.0.
Affected products
-
- Version < 1.13.5StatusaffectedConstraints-
- Version >= 1.14.0-alpha.1, < 1.14.0StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
github.com/kyverno/kyverno
Go
Introduced 0 Fixed 1.13.5github.com/kyverno/kyverno
Go
Introduced 1.14.0-alpha.1 Fixed 1.14.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/kyverno/kyverno | 0 | 1.13.5 |
| Go | github.com/kyverno/kyverno | 1.14.0-alpha.1 | 1.14.0 |
Remediation
No remediation recorded yet.
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-12613 Advisory
- https://github.com/advisories/GHSA-jrr2-x33p-6hvc Advisory
- https://github.com/kyverno/kyverno/commit/3ff923b7756e1681daf73849954bd88516589194 x_refsource_MISCPatch
- https://github.com/kyverno/kyverno/security/advisories/GHSA-jrr2-x33p-6hvc x_refsource_CONFIRMExploitVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-46342
- https://pkg.go.dev/vuln/GO-2025-3652
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-12613 | Advisory | |
| https://github.com/advisories/GHSA-jrr2-x33p-6hvc | Advisory | |
| https://github.com/kyverno/kyverno/commit/3ff923b7756e1681daf73849954bd88516589194 | x_refsource_MISCPatch | |
| https://github.com/kyverno/kyverno/security/advisories/GHSA-jrr2-x33p-6hvc | x_refsource_CONFIRMExploitVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2025-46342 | ||
| https://pkg.go.dev/vuln/GO-2025-3652 |
Change history (0)
No recorded changes yet.