Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-1725


A flaw was found in the kubevirt-csi component of OpenShift Virtualization's Hosted Control Plane (HCP). This issue could allow an authenticated attacker to gain access to the root HCP worker node's volume by creating a custom Persistent Volume that matches the name of a worker node.


Published

2024-03-07T20:15:50.690

Last Modified

2025-03-26T05:15:40.107

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-501
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application redhat openshift_container_platform 4.13 Yes
Application redhat openshift_container_platform 4.14 Yes
Application redhat openshift_container_platform 4.15 Yes
Application redhat openshift_container_platform_for_arm64 4.13 Yes
Application redhat openshift_container_platform_for_arm64 4.14 Yes
Application redhat openshift_container_platform_for_arm64 4.15 Yes
Application redhat openshift_container_platform_for_ibm_z 4.13 Yes
Application redhat openshift_container_platform_for_ibm_z 4.14 Yes
Application redhat openshift_container_platform_for_ibm_z 4.15 Yes
Application redhat openshift_container_platform_for_linuxone 4.13 Yes
Application redhat openshift_container_platform_for_linuxone 4.14 Yes
Application redhat openshift_container_platform_for_linuxone 4.15 Yes
Application redhat openshift_container_platform_for_power 4.13 Yes
Application redhat openshift_container_platform_for_power 4.14 Yes
Application redhat openshift_container_platform_for_power 4.15 Yes

References