CVE-2024-33394
Aliases:GHSA-4q63-mr2m-57hfGO-2024-2816
Advisory lineage Upstream: 0 Downstream: 5
Analyzed
Published: 02 May 2024, 00:00
Last modified:02 Aug 2024, 02:27
Vulnerability Summary
Overall Risk (default)
low
24/100 CVSS Score
5.9 MEDIUM
v3.1 (cve.org)
EPSS Score
0.32% LOW
0% probability +0.28%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
02 May 2024, 00:00
Published
Vulnerability first disclosed
02 Aug 2024, 02:27
Last Modified
Vulnerability information updated
Description
An issue in kubevirt kubevirt v1.2.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.
CVSS Metrics
- v3.1•MEDIUM•Score: 5.9CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS Trends
Current EPSS score: 0.32%• Percentile: 24%
Techniques & Countermeasures
- CWE-94•Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Affected Systems
- kubevirt.io•kubevirt
≤ 1.2.0 | all
- kubevirt•kubevirt
≤ 1.2.0