CVE-2024-1725
07.03.2024, 20:15
A flaw was found in the kubevirt-csi component of OpenShift Virtualization's Hosted Control Plane (HCP). This issue could allow an authenticated attacker to gain access to the root HCP worker node's volume by creating a custom Persistent Volume that matches the name of a worker node.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | openshift_container_platform | 4.13 |
redhat | openshift_container_platform | 4.14 |
redhat | openshift_container_platform | 4.15 |
redhat | openshift_container_platform_for_arm64 | 4.13 |
redhat | openshift_container_platform_for_arm64 | 4.14 |
redhat | openshift_container_platform_for_arm64 | 4.15 |
redhat | openshift_container_platform_for_ibm_z | 4.13 |
redhat | openshift_container_platform_for_ibm_z | 4.14 |
redhat | openshift_container_platform_for_ibm_z | 4.15 |
redhat | openshift_container_platform_for_linuxone | 4.13 |
redhat | openshift_container_platform_for_linuxone | 4.14 |
redhat | openshift_container_platform_for_linuxone | 4.15 |
redhat | openshift_container_platform_for_power | 4.13 |
redhat | openshift_container_platform_for_power | 4.14 |
redhat | openshift_container_platform_for_power | 4.15 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References