漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
KubeVirt Vulnerable to Arbitrary Host File Read and Write
Vulnerability Description
KubeVirt is a virtual machine management add-on for Kubernetes. The `hostDisk` feature in KubeVirt allows mounting a host file or directory owned by the user with UID 107 into a VM. However, prior to version 1.6.1 and 1.7.0, the implementation of this feature and more specifically the `DiskOrCreate` option (which creates a file if it doesn't exist) has a logic bug that allows an attacker to read and write arbitrary files owned by more privileged users on the host system. Versions 1.6.1 and 1.7.0 fix the issue.
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
信息暴露
Vulnerability Title
Kubevirt 安全漏洞
Vulnerability Description
Kubevirt是KubeVirt开源的一款虚拟机管理器。 Kubevirt 1.6.1之前版本和1.7.0之前版本存在安全漏洞,该漏洞源于hostDisk功能逻辑错误,可能导致读取和写入任意文件。
CVSS Information
N/A
Vulnerability Type
N/A