Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vjhf-6xfr-5p9g

Опубликовано: 03 апр. 2024
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

KubeVirt NULL pointer dereference flaw

A NULL pointer dereference flaw was found in KubeVirt. This flaw allows an attacker who has access to a virtual machine guest on a node with DownwardMetrics enabled to cause a denial of service by issuing a high number of calls to vm-dump-metrics --virtio and then deleting the virtual machine.

Пакеты

Наименование

kubevirt.io/kubevirt

go
Затронутые версииВерсия исправления

<= 1.2.0

Отсутствует

EPSS

Процентиль: 28%
0.00102
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-476

Связанные уязвимости

CVSS3: 6.5
redhat
почти 2 года назад

A NULL pointer dereference flaw was found in KubeVirt. This flaw allows an attacker who has access to a virtual machine guest on a node with DownwardMetrics enabled to cause a denial of service by issuing a high number of calls to vm-dump-metrics --virtio and then deleting the virtual machine.

CVSS3: 6.5
nvd
почти 2 года назад

A NULL pointer dereference flaw was found in KubeVirt. This flaw allows an attacker who has access to a virtual machine guest on a node with DownwardMetrics enabled to cause a denial of service by issuing a high number of calls to vm-dump-metrics --virtio and then deleting the virtual machine.

EPSS

Процентиль: 28%
0.00102
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-476