Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-849r-8wvp-4wwg

Опубликовано: 01 июн. 2021
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Permissions bypass in KubeVirt

A flaw was found in the KubeVirt main virt-handler versions before 0.26.0 regarding the access permissions of virt-handler. An attacker with access to create VMs could attach any secret within their namespace, allowing them to read the contents of that secret.

Пакеты

Наименование

kubevirt.io/kubevirt

go
Затронутые версииВерсия исправления

< 0.26.0

0.26.0

EPSS

Процентиль: 34%
0.00141
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 6.5
redhat
около 6 лет назад

A flaw was found in the KubeVirt main virt-handler versions before 0.26.0 regarding the access permissions of virt-handler. An attacker with access to create VMs could attach any secret within their namespace, allowing them to read the contents of that secret.

CVSS3: 6.5
nvd
больше 4 лет назад

A flaw was found in the KubeVirt main virt-handler versions before 0.26.0 regarding the access permissions of virt-handler. An attacker with access to create VMs could attach any secret within their namespace, allowing them to read the contents of that secret.

EPSS

Процентиль: 34%
0.00141
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-732