CVE-2024-1725
MEDIUMDescription
A flaw was found in the kubevirt-csi component of OpenShift Virtualization's Hosted Control Plane (HCP). This issue could allow an authenticated attacker to gain access to the root HCP worker node's volume by creating a custom Persistent Volume that matches the name of a worker node.
Is your site exposed to CVE-2024-1725?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| redhat | openshift_container_platform |
| redhat | openshift_container_platform |
| redhat | openshift_container_platform |
| redhat | openshift_container_platform_for_arm64 |
| redhat | openshift_container_platform_for_arm64 |
| redhat | openshift_container_platform_for_arm64 |
| redhat | openshift_container_platform_for_ibm_z |
| redhat | openshift_container_platform_for_ibm_z |
| redhat | openshift_container_platform_for_ibm_z |
| redhat | openshift_container_platform_for_linuxone |
| redhat | openshift_container_platform_for_linuxone |
| redhat | openshift_container_platform_for_linuxone |
| redhat | openshift_container_platform_for_power |
| redhat | openshift_container_platform_for_power |
| redhat | openshift_container_platform_for_power |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-1725? +
How severe is CVE-2024-1725? +
What products are affected by CVE-2024-1725? +
How do I check if I'm vulnerable to CVE-2024-1725? +
Related Vulnerabilities
go-gh is a collection of Go modules to make authoring GitHub CLI extensions easier. A security vulnerability has been identified …
An unauthenticated remote attacker can post a malicious ID to the MQTT Broker results in the creation of a new …
Visual Studio Code Python Extension Remote Code Execution Vulnerability
Artemis Java Test Sandbox versions before 1.8.0 are vulnerable to a sandbox escape when an attacker includes class files in …
Trust boundary violation in Visual Studio Code - Python extension allows an unauthorized attacker to execute code locally.
Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges locally.