First published: Mon Aug 08 2022(Updated: )
A path traversal vulnerability in KubeVirt versions up to 0.56 (and 0.55.1) on all platforms allows a user able to configure the kubevirt to read arbitrary files on the host filesystem which are publicly readable or which are readable for UID 107 or GID 107. /proc/self/<> is not accessible.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Kubevirt | >=0.20.0<0.55.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
The vulnerability ID for this KubeVirt vulnerability is CVE-2022-1798.
CVE-2022-1798 has a severity level of high.
CVE-2022-1798 affects KubeVirt versions up to 0.56 (and 0.55.1) on all platforms.
CVE-2022-1798 allows an attacker to read arbitrary files on the host filesystem that are publicly readable or readable for UID 107 or GID 107.
No, the /proc/self/<> path is not accessible in CVE-2022-1798.