Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 6

Количество 6

redhat логотип

CVE-2026-9804

2 месяца назад

A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an exported filesystem Persistent Volume Claim (PVC) that points outside its designated mount root, the attacker can read arbitrary files from the exporter pod's filesystem. This leads to information disclosure, potentially exposing sensitive data.

CVSS3: 7.7
EPSS: Низкий
nvd логотип

CVE-2026-9804

2 месяца назад

A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an exported filesystem Persistent Volume Claim (PVC) that points outside its designated mount root, the attacker can read arbitrary files from the exporter pod's filesystem. This leads to information disclosure, potentially exposing sensitive data.

CVSS3: 7.7
EPSS: Низкий
msrc логотип

CVE-2026-9804

около 2 месяцев назад

Kubevirt: kubevirt: vmexport directory symlink escape enables exporter pod file read

EPSS: Низкий
github логотип

GHSA-mpmf-3w4r-qfpf

2 месяца назад

KubeVirt has a Link Following issue

CVSS3: 7.7
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2804-1

22 дня назад

Security update for kubevirt

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2783-1

24 дня назад

Security update for kubevirt-1.6

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-9804

A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an exported filesystem Persistent Volume Claim (PVC) that points outside its designated mount root, the attacker can read arbitrary files from the exporter pod's filesystem. This leads to information disclosure, potentially exposing sensitive data.

CVSS3: 7.7
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-9804

A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an exported filesystem Persistent Volume Claim (PVC) that points outside its designated mount root, the attacker can read arbitrary files from the exporter pod's filesystem. This leads to information disclosure, potentially exposing sensitive data.

CVSS3: 7.7
1%
Низкий
2 месяца назад
msrc логотип
CVE-2026-9804

Kubevirt: kubevirt: vmexport directory symlink escape enables exporter pod file read

1%
Низкий
около 2 месяцев назад
github логотип
GHSA-mpmf-3w4r-qfpf

KubeVirt has a Link Following issue

CVSS3: 7.7
1%
Низкий
2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2804-1

Security update for kubevirt

22 дня назад
suse-cvrf логотип
SUSE-SU-2026:2783-1

Security update for kubevirt-1.6

24 дня назад

Уязвимостей на страницу