VDB
Sign up
MEDIUM5.9

GHSA-4q63-mr2m-57hf

kubevirt allows a local attacker to execute arbitrary code via a crafted command

Details

An issue in kubevirt kubevirt v1.2.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/kubevirt.io/kubevirt
Introduced in: 0

No fixed version published yet for kubevirt.io/kubevirt (go modules). Pin to a known-safe version or switch to an alternative.

References