CVE-2024-1725

A flaw was found in the kubevirt-csi component of OpenShift Virtualization's Hosted Control Plane (HCP). This issue could allow an authenticated attacker to gain access to the root HCP worker node's volume by creating a custom Persistent Volume that matches the name of a worker node.
Configurations

No configuration.

History

21 Nov 2024, 08:51

Type Values Removed Values Added
References () https://access.redhat.com/errata/RHSA-2024:1559 - () https://access.redhat.com/errata/RHSA-2024:1559 -
References () https://access.redhat.com/errata/RHSA-2024:1891 - () https://access.redhat.com/errata/RHSA-2024:1891 -
References () https://access.redhat.com/errata/RHSA-2024:2047 - () https://access.redhat.com/errata/RHSA-2024:2047 -
References () https://access.redhat.com/security/cve/CVE-2024-1725 - () https://access.redhat.com/security/cve/CVE-2024-1725 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=2265398 - () https://bugzilla.redhat.com/show_bug.cgi?id=2265398 -

08 May 2024, 02:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2024:2047 -

26 Apr 2024, 20:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2024:1891 -

03 Apr 2024, 00:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2024:1559 -

08 Mar 2024, 14:02

Type Values Removed Values Added
Summary
  • (es) Se encontró una falla en el componente kubevirt-csi del plano de control alojado (HCP) de OpenShift Virtualization. Este problema podría permitir que un atacante autenticado obtenga acceso al volumen del nodo trabajador HCP raíz mediante la creación de un volumen persistente personalizado que coincida con el nombre de un nodo trabajador.

07 Mar 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-07 20:15

Updated : 2024-11-21 08:51


NVD link : CVE-2024-1725

Mitre link : CVE-2024-1725

CVE.ORG link : CVE-2024-1725


JSON object : View

Products Affected

No product.

CWE
CWE-501

Trust Boundary Violation