Kyverno’s container image signature verification can be bypassed

Mar 1, 2023

Jonathan Kaftzan
VP Marketing & Business Development

Dec 21, 2022 – The vulnerability enables an attacker who is either running a malicious container image registry or is able to act as a proxy between the registry and Kyverno, to inject unsigned images into the protected cluster, bypassing the image verification policy.