CVE-2023-54356
Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites (TLSECDHERSAWITH3DESEDECBCSHA and TLSRSAWITH3DESEDECBC_SHA) on their TLS endpoints. These 64-bit block ciphers are vulnerable to the Sweet32 attack (CVE-2016-2183), which, over very long-lived TLS connections carrying large volumes of traffic, could allow an attacker to recover small amounts of plaintext. The issue is fixed in Kyverno 1.9.5 and 1.10.0.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/54xxx/CVE-2023-54356.json, https://github.com/kyverno/kyverno/security/advisories/GHSA-hgv6-w7r3-w4qw, https://nvd.nist.gov/vuln/detail/CVE-2023-54356, https://www.vulncheck.com/advisories/kyverno-before-1.9.5-sweet32-medium-strength-cipher-suites