Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 7

Количество 7

github логотип

GHSA-7jcp-v9w4-wjmg

2 месяца назад

KubeVirt has a Link Following vulnerability

CVSS3: 9.9
EPSS: Низкий
redhat логотип

CVE-2026-7374

2 месяца назад

A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket with a symlink to the host's container runtime (CRI-O) socket, an attacker can hijack virt-handler's privileged connection. This enables the attacker to access any Unix socket on the host, potentially leading to full control of the node and the entire cluster.

CVSS3: 9.9
EPSS: Низкий
nvd логотип

CVE-2026-7374

2 месяца назад

A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket with a symlink to the host's container runtime (CRI-O) socket, an attacker can hijack virt-handler's privileged connection. This enables the attacker to access any Unix socket on the host, potentially leading to full control of the node and the entire cluster.

CVSS3: 9.9
EPSS: Низкий
msrc логотип

CVE-2026-7374

2 месяца назад

Kubevirt: kubevirt virt-handler: privilege escalation and node compromise via symlink following vulnerability

CVSS3: 9.9
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2077-1

2 месяца назад

Security update for kubevirt

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2401-1

около 2 месяцев назад

Security update for kubevirt-1.6

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2400-1

около 2 месяцев назад

Security update for kubevirt

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-7jcp-v9w4-wjmg

KubeVirt has a Link Following vulnerability

CVSS3: 9.9
1%
Низкий
2 месяца назад
redhat логотип
CVE-2026-7374

A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket with a symlink to the host's container runtime (CRI-O) socket, an attacker can hijack virt-handler's privileged connection. This enables the attacker to access any Unix socket on the host, potentially leading to full control of the node and the entire cluster.

CVSS3: 9.9
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-7374

A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket with a symlink to the host's container runtime (CRI-O) socket, an attacker can hijack virt-handler's privileged connection. This enables the attacker to access any Unix socket on the host, potentially leading to full control of the node and the entire cluster.

CVSS3: 9.9
1%
Низкий
2 месяца назад
msrc логотип
CVE-2026-7374

Kubevirt: kubevirt virt-handler: privilege escalation and node compromise via symlink following vulnerability

CVSS3: 9.9
1%
Низкий
2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2077-1

Security update for kubevirt

1%
Низкий
2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2401-1

Security update for kubevirt-1.6

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:2400-1

Security update for kubevirt

около 2 месяцев назад

Уязвимостей на страницу