One Article Review

Accueil - L'article:
Source CVE.webp CVE Liste
Identifiant 6133263
Date de publication 2022-08-04 22:15:08 (vue: 2022-08-05 01:06:38)
Titre CVE-2022-35930
Texte PolicyController is a utility used to enforce supply chain policy in Kubernetes clusters. In versions prior to 0.2.1 PolicyController will report a false positive, resulting in an admission when it should not be admitted when there is at least one attestation with a valid signature and there are NO attestations of the type being verified (--type defaults to "custom"). An example image that can be used to test this is `ghcr.io/distroless/static@sha256:dd7614b5a12bc4d617b223c588b4e0c833402b8f4991fb5702ea83afad1986e2`. Users should upgrade to version 0.2.1 to resolve this issue. There are no workarounds for users unable to upgrade.
Envoyé Oui
Condensat 2022 35930 `ghcr admission admitted are attestation attestations being can chain clusters custom cve defaults enforce example false image io/distroless/static@sha256:dd7614b5a12bc4d617b223c588b4e0c833402b8f4991fb5702ea83afad1986e2` issue kubernetes least not one policy policycontroller positive prior report resolve resulting should signature supply test type unable upgrade used users utility valid verified version versions when will workarounds
Tags
Stories Uber
Notes
Move


L'article ne semble pas avoir été repris aprés sa publication.


L'article ne semble pas avoir été repris sur un précédent.
My email: