Skip to main content

Trust Boundary Violation

CVE-2024-1725

Severity Medium
Score 6.5/10

Summary

A flaw was found in the kubevirt-csi component of OpenShift Virtualization's Hosted Control Plane (HCP). This issue could allow an authenticated attacker to gain access to the root HCP worker node's volume by creating a custom Persistent Volume that matches the name of a worker node This issue affects github.com/kubevirt/csi-driver version prior to 0.0.0-202403081943-cc28dcbb0afc14.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • LOW
  • HIGH
  • NONE

CWE-501 - Trust Boundary Violation

The product mixes trusted and untrusted data in the same data structure or structured message.

Advisory Timeline

  • Published