MEDIUM5.9
GHSA-4q63-mr2m-57hf
kubevirt allows a local attacker to execute arbitrary code via a crafted command
Details
An issue in kubevirt kubevirt v1.2.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/kubevirt.io/kubevirt
Introduced in:
0No fixed version published yet for kubevirt.io/kubevirt (go modules). Pin to a known-safe version or switch to an alternative.