CVE-2022-47633
NixOS vulnerability analysis and mitigation

Overview

An image signature validation bypass vulnerability in Kyverno versions 1.8.3 and 1.8.4, tracked as CVE-2022-47633, allows a malicious image registry or a man-in-the-middle attacker to bypass signature verification mechanisms. The vulnerability was discovered in December 2022 and affects the Kyverno admission controller for container images, which is used to enforce policies for Kubernetes clusters (GitHub Advisory).

Technical details

The vulnerability exists in Kyverno's verifyImages rules used for verification, which cannot prevent unknown registries. When the admission controller validates an image, it requests a signature from the container registry and the image manifest to get the image hash. However, a malicious registry can return a signature for a signed image but then provide a manifest for an unsigned, malicious image during the mutation phase (SOCRadar).

Impact

Successful exploitation of CVE-2022-47633 could allow attackers to hijack victim pods and utilize all their resources, including credentials and API tokens. This could ultimately lead to supply chain compromise by allowing unsigned malicious container images to be deployed in the cluster (SOCRadar).

Mitigation and workarounds

The vulnerability was patched in Kyverno version 1.8.5, which ensures that the same image hash used to verify signatures is also used to modify the workload specification. As a workaround, users can configure a Kyverno policy to restrict registries to a set of secure trusted image registries. Users are advised to update to the latest version as soon as possible (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-61619HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-61618HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-61617HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-61610HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-61609HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management