The following table lists the changes that have been made to the
CVE-2025-29778 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.
-
New CVE Received
by [email protected]Mar. 24, 2025
Action Type Old Value New Value Added Description Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to version 1.14.0-alpha.1, Kyverno ignores subjectRegExp and IssuerRegExp while verifying artifact’s sign with keyless mode. It allows the attacker to deploy kubernetes resources with the artifacts that were signed by unexpected certificate. Deploying these unauthorized kubernetes resources can lead to full compromise of kubernetes cluster. Version 1.14.0-alpha.1 contains a patch for the issue. Added CVSS V3.1 AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N Added CWE CWE-285 Added Reference https://github.com/kyverno/kyverno/commit/8777672fb17bdf252bd2e7d8de3441e240404a60 Added Reference https://github.com/kyverno/kyverno/pull/12237 Added Reference https://github.com/kyverno/kyverno/security/advisories/GHSA-46mp-8w32-6g94 Added Reference https://github.com/kyverno/policies/issues/1246 Added Reference https://github.com/Mohdcode/kyverno/blob/373f942ea9fa8b63140d0eb0e101b9a5f71033f3/pkg/cosign/cosign.go#L537