Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-31419

Опубликовано: 03 апр. 2024
Источник: redhat
CVSS3: 4.3

Описание

An information disclosure flaw was found in OpenShift Virtualization. The DownwardMetrics feature was introduced to expose host metrics to virtual machine guests and is enabled by default. This issue could expose limited host metrics of a node to any guest in any namespace without being explicitly enabled by an administrator.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Virtualization 4kubevirt-hyperconverged-cluster-operatorAffected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-497
https://bugzilla.redhat.com/show_bug.cgi?id=2272948cnv: information disclosure through the usage of vm-dump-metrics

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
около 2 лет назад

An information disclosure flaw was found in OpenShift Virtualization. The DownwardMetrics feature was introduced to expose host metrics to virtual machine guests and is enabled by default. This issue could expose limited host metrics of a node to any guest in any namespace without being explicitly enabled by an administrator.

CVSS3: 4.3
github
около 2 лет назад

An information disclosure flaw was found in OpenShift Virtualization. The DownwardMetrics feature was introduced to expose host metrics to virtual machine guests and is enabled by default. This issue could expose limited host metrics of a node to any guest in any namespace without being explicitly enabled by an administrator.

4.3 Medium

CVSS3