Nirmata's vulnerability footprint centers on Kyverno, a Kubernetes policy engine and admission controller that operates within container orchestration environments. Its disclosed issues cluster around authorization and access-control mechanisms—improper authorization, access-control flaws, and infinite-loop conditions—reflecting the policy-enforcement and request-validation role the product plays in Kubernetes clusters. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nirmata over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-33191HIGH Kyverno is a policy engine designed for Kubernetes. Kyverno seccomp control can be circumvented. Users of the podSecurity `validate.podSecurity` subrule in Kyverno 1.9.2 and 1.9.3 | May 30, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-34091MEDIUM Kyverno is a policy engine designed for Kubernetes. In versions of Kyverno prior to 1.10.0, resources which have the `deletionTimestamp` field defined can bypass validate, generate | Jun 1, 2023 | 6.5 | 22 | NO | NO |
CVE-2023-42815MEDIUM Kyverno is a policy engine designed for Kubernetes. A security vulnerability was found in Kyverno where an attacker could cause denial of service of Kyverno. The vulnerability was | Nov 13, 2023 | 5.3 | 18 | NO | NO |
CVE-2023-42814MEDIUM Kyverno is a policy engine designed for Kubernetes. A security vulnerability was found in Kyverno where an attacker could cause denial of service of Kyverno. The vulnerable compone | Nov 13, 2023 | 5.3 | 18 | NO | NO |
CVE-2023-42816MEDIUM Kyverno is a policy engine designed for Kubernetes. A security vulnerability was found in Kyverno where an attacker could cause denial of service of Kyverno. The vulnerability was | Nov 13, 2023 | 5.3 | 17 | NO | NO |
CVE-2023-42813MEDIUM Kyverno is a policy engine designed for Kubernetes. A security vulnerability was found in Kyverno where an attacker could cause denial of service of Kyverno. The vulnerable compone | Nov 13, 2023 | 5.3 | 15 | NO | NO |
Kyverno is a policy engine designed for Kubernetes. A kyverno ClusterPolicy, ie. "disallow-privileged-containers," can be overridden by the creation of a PolicyException in a rando | Oct 29, 2024 | 2.7 | 14 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nirmata.
Media articles that mention a CVE ID that affects a product developed by Nirmata — matched by CVE ID, not by vendor name.