Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-1798

Опубликовано: 15 сент. 2022
Источник: nvd
CVSS3: 8.7
CVSS3: 6.5
EPSS Низкий

Описание

A path traversal vulnerability in KubeVirt versions up to 0.56 (and 0.55.1) on all platforms allows a user able to configure the kubevirt to read arbitrary files on the host filesystem which are publicly readable or which are readable for UID 107 or GID 107. /proc/self/<> is not accessible.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:kubevirt:kubevirt:*:*:*:*:*:kubernetes:*:*
Версия от 0.20.0 (включая) до 0.55.1 (исключая)

EPSS

Процентиль: 34%
0.00139
Низкий

8.7 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-20
CWE-22

Связанные уязвимости

CVSS3: 7.7
redhat
больше 3 лет назад

A path traversal vulnerability in KubeVirt versions up to 0.56 (and 0.55.1) on all platforms allows a user able to configure the kubevirt to read arbitrary files on the host filesystem which are publicly readable or which are readable for UID 107 or GID 107. /proc/self/<> is not accessible.

CVSS3: 6.5
msrc
больше 3 лет назад

Path Traversal vulnerability in Kubevirt

CVSS3: 6.5
github
больше 3 лет назад

Duplicate Advisory: KubeVirt arbitrary host file read from the VM

suse-cvrf
больше 3 лет назад

Security update for kubevirt, virt-api-container, virt-controller-container, virt-handler-container, virt-launcher-container, virt-libguestfs-tools-container, virt-operator-container

suse-cvrf
больше 3 лет назад

Security update for kubevirt, virt-api-container, virt-controller-container, virt-handler-container, virt-launcher-container, virt-libguestfs-tools-container, virt-operator-container

EPSS

Процентиль: 34%
0.00139
Низкий

8.7 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-20
CWE-22