CVE-2024-1725
CVSS V2 None
CVSS V3 None
Description
A flaw was found in the kubevirt-csi component of OpenShift Virtualization's Hosted Control Plane (HCP). This issue could allow an authenticated attacker to gain access to the root HCP worker node's volume by creating a custom Persistent Volume that matches the name of a worker node.
Overview
- CVE ID
- CVE-2024-1725
- Assigner
- redhat
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-03-07T20:09:11.616Z
- Last Modified Date
- 2024-05-08T01:51:31.044Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://access.redhat.com/errata/RHSA-2024:1559 | vendor-advisory x_refsource_REDHAT |
https://access.redhat.com/errata/RHSA-2024:1891 | vendor-advisory x_refsource_REDHAT |
https://access.redhat.com/errata/RHSA-2024:2047 | vendor-advisory x_refsource_REDHAT |
https://access.redhat.com/security/cve/CVE-2024-1725 | vdb-entry x_refsource_REDHAT |
https://bugzilla.redhat.com/show_bug.cgi?id=2265398 | issue-tracking x_refsource_REDHAT |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-1725 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1725 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-26 06:00:07 | Added to TrackCVE |