Product
A vulnerability in Kyverno v1.18.0 and v1.18.1 allows a namespace-scoped user to execute arbitrary resource creation across the entire cluster by exploiting an unvalidated namespace argument in CEL expressions.