Vulnerabilidades em kubevirt
9 resultadosAnálise Vexday
KubeVirt registra 8 vulnerabilidades acumuladas na base Vexday, todas fora de exploração ativa conhecida. A fraqueza dominante é autenticação inadequada (CWE-287), indicando problemas estruturais no mecanismo de controle de acesso. Nenhuma vulnerabilidade crítica foi identificada e o panorama não apresenta novidades recentes, sugerindo risco estável mas que requer atenção ao modelo de autenticação do projeto.
CVE-2019-10175MEDIUMA flaw was found in the containerized-data-importer in virt-cdi-cloner, version 1.4, where the host-assisted cloning feature does not determEPSS 1.0%CVE-2023-26484HIGHOn a compromised KubeVirt node, the virt-handler service account can be used to modify all node specsEPSS 0.6%CVE-2025-64433MEDIUMKubeVirt Arbitrary Container File ReadEPSS 0.5%CVE-2025-64435MEDIUMKubeVirt VMI Denial-of-Service (DoS) Using Pod ImpersonationEPSS 0.4%CVE-2025-64436MEDIUMKubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between NodesEPSS 0.3%CVE-2025-64324HIGHKubeVirt Vulnerable to Arbitrary Host File Read and WriteEPSS 0.2%CVE-2025-64437MEDIUMKubeVirt Isolation Detection Flaw Allows Arbitrary File Permission ChangesEPSS 0.2%CVE-2025-64434MEDIUMKubeVirt Improper TLS Certificate Management Handling Allows API Identity SpoofingEPSS 0.2%CVE-2025-64432MEDIUMKubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation LayerEPSS 0.1%