icon

We found results for “

CVE-2024-1725

Good to know:

icon

Date: March 7, 2024

A flaw was found in the kubevirt-csi component of OpenShift Virtualization's Hosted Control Plane (HCP). This issue could allow an authenticated attacker to gain access to the root HCP worker node's volume by creating a custom Persistent Volume that matches the name of a worker node.

Language: Go

Severity Score

Severity Score

Weakness Type (CWE)

Trust Boundary Violation

CWE-501

Top Fix

icon

Upgrade Version

Upgrade to version cc28dcbb0afca0a7cb8a73bc998ab49f864ed560

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): LOW
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): HIGH
Integrity (I): HIGH
Availability (A): NONE

Do you need more information?

Contact Us