The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade github.com/kyverno/kyverno
to version 1.10.5 or higher.
Affected versions of this package are vulnerable to Information Exposure when the digest of images
is manipulated. An attacker can cause a user to unintentionally consume an insecure image by compromising the registry from which the images are fetched.
Note:
This is only exploitable if the attacker knows which images the user consumes and is aware of exploitable vulnerabilities in previous digests of the images. Alternatively, the attacker could craft a malicious image with a different digest with intentionally placed vulnerabilities and deliver the image to the user. This vulnerability does not allow the attacker to control other parameters of the image other than the digest.
Users pulling their images from trusted registries are not impacted by this vulnerability. There is no evidence of this being exploited in the wild.