MEDIUM 5.9 Go

kubevirt allows a local attacker to execute arbitrary code via a crafted command

GHSA-4q63-mr2m-57hf · CVE-2024-33394 · GO-2024-2816

Published · Modified

Description

An issue in kubevirt kubevirt v1.2.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.

Ready to move

Start Securing

Free, no credit card | First findings in minutes