CVE-2019-3841: High severity kubevirt containerized data importer vulnerability
Kubevirt/virt-cdi-importer, versions 1.4.0 to 1.5.3 inclusive, were reported to disable TLS certificate validation when importing data into PVCs from container registries. This could enable man-in-the-middle attacks between a container registry and the virt-cdi-component, leading to possible undetected tampering of trusted container image content.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-3841?
CVE-2019-3841 is a vulnerability in Kubevirt/virt-cdi-importer versions 1.4.0 to 1.5.3 that disables TLS certificate validation when importing data into PVCs from container registries.
What is the severity of CVE-2019-3841?
The severity of CVE-2019-3841 is high with a CVSS score of 6.8.
How does CVE-2019-3841 affect Kubevirt/virt-cdi-importer?
CVE-2019-3841 affects Kubevirt/virt-cdi-importer versions 1.4.0 to 1.5.3 by enabling man-in-the-middle attacks between a container registry and the virt-cdi-component.
How can CVE-2019-3841 be exploited?
CVE-2019-3841 can be exploited by an attacker who performs a man-in-the-middle attack between the container registry and the virt-cdi-component.
How can I fix CVE-2019-3841?
To fix CVE-2019-3841, upgrade Kubevirt/virt-cdi-importer to a version above 1.5.3 that addresses the TLS certificate validation issue.