CVE-2024-33394

MEDIUM5.9EPSS 0.04%

kubevirt allows a local attacker to execute arbitrary code via a crafted command

Published: 5/2/2024Modified: 7/3/2024
Also known as:GHSA-4q63-mr2m-57hfGO-2024-2816

Description

An issue in kubevirt kubevirt v1.2.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.9CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

References (4)