Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-1701

Опубликовано: 07 янв. 2020
Источник: redhat
CVSS3: 6.5

Описание

A flaw was found in the KubeVirt main virt-handler versions before 0.26.0 regarding the access permissions of virt-handler. An attacker with access to create VMs could attach any secret within their namespace, allowing them to read the contents of that secret.

A flaw was found in the KubeVirt main virt-handler regarding the access permissions of virt-handler. An attacker with access to create VMs could attach any secret within their namespace, allowing them to read the contents of that secret.

Меры по смягчению последствий

This issue can only be resolved by applying updates. Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Virtualization 1virt-handlerFix deferred
Red Hat OpenShift Virtualization 2virt-handler-containerAffected
Red Hat OpenShift Virtualization 2kubevirt-cpu-model-nfd-plugin-containerFixedRHEA-2020:201104.05.2020
Red Hat OpenShift Virtualization 2kubevirt-cpu-node-labeller-containerFixedRHEA-2020:201104.05.2020
Red Hat OpenShift Virtualization 2kubevirt-kvm-info-nfd-plugin-containerFixedRHEA-2020:201104.05.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-732
https://bugzilla.redhat.com/show_bug.cgi?id=1792092virt-handler: virt-handler daemonset clusterroles allows retrieval of secrets

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
больше 4 лет назад

A flaw was found in the KubeVirt main virt-handler versions before 0.26.0 regarding the access permissions of virt-handler. An attacker with access to create VMs could attach any secret within their namespace, allowing them to read the contents of that secret.

CVSS3: 6.5
github
больше 4 лет назад

Permissions bypass in KubeVirt

6.5 Medium

CVSS3