In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade github.com/kubewarden/kubewarden-controller/api/policies/v1
to version 1.21.0-rc2 or higher.
Affected versions of this package are vulnerable to Incorrect Permission Assignment for Critical Resource in policy_validation.go
, which allows an attacker to prevent the creation and update of PolicyReport
objects to hide non-compliant resources. This is possible by abusing an AdmissionPolicy
or AdmissionPolicyGroup
, which evaluate namespaced resources. It is also possible to abuse an AdmissionPolicy
to alter the contents of the PolicyReports
created in the namespace.