CVE-2024-33394: Code Injection
Published May 2, 2024
·Updated
An issue in kubevirt kubevirt v1.2.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.
Affected Software
2 affected components
go/kubevirt.io/kubevirt<=1.2.0
Kubevirt Kubevirt Kubernetes<=1.2.0
Event History
May 2, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
Affected Software
Advisory Published
via GitHub·06:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-33394?
The severity of CVE-2024-33394 is critical due to its ability to allow local attackers to execute arbitrary code.
2
How do I fix CVE-2024-33394?
To fix CVE-2024-33394, upgrade kubevirt to version 1.2.1 or later.
3
Who is affected by CVE-2024-33394?
CVE-2024-33394 affects users of kubevirt versions 1.2.0 and earlier.
4
What systems are impacted by CVE-2024-33394?
CVE-2024-33394 impacts systems using Kubevirt with Kubernetes.
5
What type of vulnerability is CVE-2024-33394?
CVE-2024-33394 is a local privilege escalation vulnerability.