PT-2021-10077 · Kubevirt · Kubevirt

Published

2021-05-27

·

Updated

2024-06-04

·

CVE-2020-1701

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: KubeVirt versions prior to 0.26.0
Description: A flaw was found in the KubeVirt main virt-handler regarding access permissions, allowing an attacker with access to create VMs to attach any secret within their namespace and read its contents. This issue concerns a permissions bypass in KubeVirt.
Recommendations: For versions prior to 0.26.0, update to version 0.26.0 or later to resolve the issue. As a temporary workaround, consider restricting access to create VMs and secrets within namespaces to minimize the risk of exploitation.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-1701
GHSA-849R-8WVP-4WWG
GO-2024-2765

Affected Products

Kubevirt