PT-2020-13972 · Kubevirt · Kubevirt

Stoyan Nikolov

·

Published

2020-07-29

·

Updated

2024-06-04

·

CVE-2020-14316

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions kubevirt versions 0.29 and earlier
Description A flaw in kubevirt allows Virtual Machine Instances (VMIs) to be used to gain access to the host's filesystem. Successful exploitation enables an attacker to assume the privileges of the VM process on the host system, potentially reading and modifying any file on the system where the VMI is running. This poses a significant threat to data confidentiality and integrity, as well as system availability.
Recommendations For kubevirt versions 0.29 and earlier, consider restricting access to Virtual Machine Instances (VMIs) to minimize the risk of exploitation until a patch is available. As a temporary workaround, consider implementing additional security measures to limit the privileges of the VM process on the host system.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-14316
GHSA-828R-R2C8-RFW3
GO-2024-2756

Affected Products

Kubevirt