VDB
KO

GO-2023-2340

Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno

Quick fix

GO-2023-2340 — github.com/kyverno/kyverno: upgrade to the fixed version with the command below.

go get github.com/kyverno/kyverno@v1.10.5

Details

Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno

Are you affected?

Enter the version of the package you're using.

Affected packages

Go / github.com/kyverno/kyverno
Introduced in: 0 Fixed in: 1.10.5
Fix go get github.com/kyverno/kyverno@v1.10.5

References