BIT-kyverno-2026-100703

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/kyverno/BIT-kyverno-2026-100703.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-kyverno-2026-100703
Aliases
Published
2026-10-01T09:26:23Z
Modified
2026-10-01T10:10:43Z
Summary
Kyverno before 1.19.1 Cross-Namespace Data Access via globalcontext.Lib
Details

Kyverno 1.16.0 through 1.19.0 registers the globalcontext.Lib CEL library in its policy environment without confining it to the policy's namespace, unlike the sibling libraries (resource.Lib, http.Lib, configMap loader) which are handed the policy namespace. A tenant who can create a namespaced policy (e.g. NamespacedValidatingPolicy, and likewise the namespaced mutating, deleting, generating, and image-validating policy kinds) in their own namespace can call globalContext.get("", "") and receive the full cached contents of a cluster-scoped GlobalContextEntry, including data cached from namespaces the tenant has no RBAC permission to read. No admission validation rejects such calls. Fixed in 1.19.1.

Database specific
{
    "cpes": [
        "cpe:2.3:a:kyverno:kyverno:*:*:*:*:*:go:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / kyverno

Package

Name
kyverno
Purl
pkg:bitnami/kyverno

Severity

  • 8.3 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
1.16.0
Fixed
1.19.1

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/kyverno/BIT-kyverno-2026-100703.json"