PT-2024-25229 · Kubevirt+1 · Kubevirt+1

Houqiyua

·

Published

2024-05-02

·

Updated

2024-07-08

·

CVE-2024-33394

CVSS v3.1

5.9

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions kubevirt versions 1.2.0 and earlier
Description The issue allows a local attacker to execute arbitrary code via a crafted command to get the token component. This can be done by sending a crafted command to the /kubevirt.io/kubevirt API endpoint. The attacker can exploit this issue to gain unauthorized access and execute arbitrary code.
Recommendations For versions 1.2.0 and earlier, consider disabling the kubevirt component until a patch is available. Restrict access to the /kubevirt.io/kubevirt API endpoint to minimize the risk of exploitation. Avoid using crafted commands to get the token component until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Weakness Enumeration

Related Identifiers

AZL-64787
AZL-64791
CVE-2024-33394
GHSA-4Q63-MR2M-57HF
GO-2024-2816
OPENSUSE-SU-2024:14058-1
SUSE-SU-2024:2246-1
SUSE-SU-2024:2318-1
SUSE-SU-2024_2246-1
SUSE-SU-2024_2318-1

Affected Products

Suse
Kubevirt