Логотип exploitDog
bind:CVE-2025-64436
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-64436

Количество 3

Количество 3

nvd логотип

CVE-2025-64436

около 1 месяца назад

KubeVirt is a virtual machine management add-on for Kubernetes. In 1.5.0 and earlier, the permissions granted to the virt-handler service account, such as the ability to update VMI and patch nodes, could be abused to force a VMI migration to an attacker-controlled node. This vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2025-64436

15 дней назад

KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes

EPSS: Низкий
github логотип

GHSA-7xgm-5prm-v5gc

около 1 месяца назад

KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-64436

KubeVirt is a virtual machine management add-on for Kubernetes. In 1.5.0 and earlier, the permissions granted to the virt-handler service account, such as the ability to update VMI and patch nodes, could be abused to force a VMI migration to an attacker-controlled node. This vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node.

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
msrc логотип
CVE-2025-64436

KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes

0%
Низкий
15 дней назад
github логотип
GHSA-7xgm-5prm-v5gc

KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes

CVSS3: 5.3
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу