Permissions bypass in KubeVirt
Moderate severity
GitHub Reviewed
Published
Jun 1, 2021
to the GitHub Advisory Database
•
Updated Apr 24, 2024
Description
Published by the National Vulnerability Database
May 27, 2021
Published to the GitHub Advisory Database
Jun 1, 2021
Reviewed
Apr 24, 2024
Last updated
Apr 24, 2024
A flaw was found in the KubeVirt main virt-handler versions before 0.26.0 regarding the access permissions of virt-handler. An attacker with access to create VMs could attach any secret within their namespace, allowing them to read the contents of that secret.
References