MEDIUM 5.9 Go
kubevirt allows a local attacker to execute arbitrary code via a crafted command
GHSA-4q63-mr2m-57hf · CVE-2024-33394 · GO-2024-2816
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
An issue in kubevirt kubevirt v1.2.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.
Ready to move
Start Securing
Free, no credit card | First findings in minutes