ZeroHour

CVE-2024-1725

CVSS 3.1
6.5 medium
EPSS
<1%p48
Published
()
Modified
Description

A flaw was found in the kubevirt-csi component of OpenShift Virtualization's Hosted Control Plane (HCP). This issue could allow an authenticated attacker to gain access to the root HCP worker node's volume by creating a custom Persistent Volume that matches the name of a worker node.

Vendors
redhat
Products
openshift container platform, openshift container platform for arm64, openshift container platform for ibm z, openshift container platform for linuxone, openshift container platform for power
Weakness
CWE-501
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.