Логотип exploitDog
bind:CVE-2025-64436
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-64436

Количество 4

Количество 4

redhat логотип

CVE-2025-64436

5 месяцев назад

KubeVirt is a virtual machine management add-on for Kubernetes. In 1.5.0 and earlier, the permissions granted to the virt-handler service account, such as the ability to update VMI and patch nodes, could be abused to force a VMI migration to an attacker-controlled node. This vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-64436

5 месяцев назад

KubeVirt is a virtual machine management add-on for Kubernetes. In 1.5.0 and earlier, the permissions granted to the virt-handler service account, such as the ability to update VMI and patch nodes, could be abused to force a VMI migration to an attacker-controlled node. This vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2025-64436

4 месяца назад

KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-7xgm-5prm-v5gc

5 месяцев назад

KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2025-64436

KubeVirt is a virtual machine management add-on for Kubernetes. In 1.5.0 and earlier, the permissions granted to the virt-handler service account, such as the ability to update VMI and patch nodes, could be abused to force a VMI migration to an attacker-controlled node. This vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node.

CVSS3: 6.5
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2025-64436

KubeVirt is a virtual machine management add-on for Kubernetes. In 1.5.0 and earlier, the permissions granted to the virt-handler service account, such as the ability to update VMI and patch nodes, could be abused to force a VMI migration to an attacker-controlled node. This vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node.

CVSS3: 5.3
0%
Низкий
5 месяцев назад
msrc логотип
CVE-2025-64436

KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes

CVSS3: 5.3
0%
Низкий
4 месяца назад
github логотип
GHSA-7xgm-5prm-v5gc

KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes

CVSS3: 5.3
0%
Низкий
5 месяцев назад

Уязвимостей на страницу