Vulnerability Description
Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites (TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA and TLS_RSA_WITH_3DES_EDE_CBC_SHA) on their TLS endpoints. These 64-bit block ciphers are vulnerable to the Sweet32 attack (CVE-2016-2183), which, over very long-lived TLS connections carrying large volumes of traffic, could allow an attacker to recover small amounts of plaintext. The issue is fixed in Kyverno 1.9.5 and 1.10.0.
CVSS Score
LOW
Related Weaknesses (CWE)
References
- https://github.com/kyverno/kyverno/security/advisories/GHSA-hgv6-w7r3-w4qw
- https://www.vulncheck.com/advisories/kyverno-before-1.9.5-sweet32-medium-strengt
FAQ
What is CVE-2023-54356?
CVE-2023-54356 is a vulnerability with a CVSS score of 3.7 (LOW). Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites (TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA and TLS_RSA_WITH_3DES_EDE_CBC_SHA) on their TLS endpoints. These 64-bit block ciphers are vu...
How severe is CVE-2023-54356?
CVE-2023-54356 has been rated LOW with a CVSS base score of 3.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-54356?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.