Vulnerability Description
A path traversal vulnerability in KubeVirt versions up to 0.56 (and 0.55.1) on all platforms allows a user able to configure the kubevirt to read arbitrary files on the host filesystem which are publicly readable or which are readable for UID 107 or GID 107. /proc/self/<> is not accessible.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kubevirt | Kubevirt | >= 0.20.0, < 0.55.1 |
Related Weaknesses (CWE)
References
- https://github.com/kubevirt/kubevirt/security/advisories/GHSA-qv98-3369-g364ExploitMitigationPatch
- https://github.com/kubevirt/kubevirt/security/advisories/GHSA-qv98-3369-g364ExploitMitigationPatch
FAQ
What is CVE-2022-1798?
CVE-2022-1798 is a vulnerability with a CVSS score of 8.7 (HIGH). A path traversal vulnerability in KubeVirt versions up to 0.56 (and 0.55.1) on all platforms allows a user able to configure the kubevirt to read arbitrary files on the host filesystem which are publi...
How severe is CVE-2022-1798?
CVE-2022-1798 has been rated HIGH with a CVSS base score of 8.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-1798?
Check the references section above for vendor advisories and patch information. Affected products include: Kubevirt Kubevirt.