PT-2020-13972 · Kubevirt · Kubevirt
Stoyan Nikolov
·
Published
2020-07-29
·
Updated
2024-06-04
·
CVE-2020-14316
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
kubevirt versions 0.29 and earlier
Description
A flaw in kubevirt allows Virtual Machine Instances (VMIs) to be used to gain access to the host's filesystem. Successful exploitation enables an attacker to assume the privileges of the VM process on the host system, potentially reading and modifying any file on the system where the VMI is running. This poses a significant threat to data confidentiality and integrity, as well as system availability.
Recommendations
For kubevirt versions 0.29 and earlier, consider restricting access to Virtual Machine Instances (VMIs) to minimize the risk of exploitation until a patch is available.
As a temporary workaround, consider implementing additional security measures to limit the privileges of the VM process on the host system.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kubevirt