Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-1701

Опубликовано: 27 мая 2021
Источник: nvd
CVSS3: 6.5
CVSS2: 4
EPSS Низкий

Описание

A flaw was found in the KubeVirt main virt-handler versions before 0.26.0 regarding the access permissions of virt-handler. An attacker with access to create VMs could attach any secret within their namespace, allowing them to read the contents of that secret.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:kubevirt:kubevirt:*:*:*:*:*:kubernetes:*:*
Версия до 0.26.0 (исключая)

EPSS

Процентиль: 34%
0.00141
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 6.5
redhat
около 6 лет назад

A flaw was found in the KubeVirt main virt-handler versions before 0.26.0 regarding the access permissions of virt-handler. An attacker with access to create VMs could attach any secret within their namespace, allowing them to read the contents of that secret.

CVSS3: 6.5
github
больше 4 лет назад

Permissions bypass in KubeVirt

EPSS

Процентиль: 34%
0.00141
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-732