Vulnerability Details CVE-2022-1798
A path traversal vulnerability in KubeVirt versions up to 0.56 (and 0.55.1) on all platforms allows a user able to configure the kubevirt to read arbitrary files on the host filesystem which are publicly readable or which are readable for UID 107 or GID 107. /proc/self/<> is not accessible.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 8.9%
CVSS Severity
CVSS v3 Score 8.7
Products affected by CVE-2022-1798
-
cpe:2.3:a:kubevirt:kubevirt:0.20.0
-
cpe:2.3:a:kubevirt:kubevirt:0.20.1
-
cpe:2.3:a:kubevirt:kubevirt:0.20.2
-
cpe:2.3:a:kubevirt:kubevirt:0.20.3
-
cpe:2.3:a:kubevirt:kubevirt:0.20.4
-
cpe:2.3:a:kubevirt:kubevirt:0.20.5
-
cpe:2.3:a:kubevirt:kubevirt:0.20.6
-
cpe:2.3:a:kubevirt:kubevirt:0.20.7
-
cpe:2.3:a:kubevirt:kubevirt:0.20.8
-
cpe:2.3:a:kubevirt:kubevirt:0.21.0
-
cpe:2.3:a:kubevirt:kubevirt:0.22.0
-
cpe:2.3:a:kubevirt:kubevirt:0.23.0
-
cpe:2.3:a:kubevirt:kubevirt:0.23.1
-
cpe:2.3:a:kubevirt:kubevirt:0.23.2
-
cpe:2.3:a:kubevirt:kubevirt:0.23.3
-
cpe:2.3:a:kubevirt:kubevirt:0.24.0
-
cpe:2.3:a:kubevirt:kubevirt:0.25.0
-
cpe:2.3:a:kubevirt:kubevirt:0.26.0
-
cpe:2.3:a:kubevirt:kubevirt:0.26.1
-
cpe:2.3:a:kubevirt:kubevirt:0.26.2
-
cpe:2.3:a:kubevirt:kubevirt:0.26.3
-
cpe:2.3:a:kubevirt:kubevirt:0.26.4
-
cpe:2.3:a:kubevirt:kubevirt:0.26.5
-
cpe:2.3:a:kubevirt:kubevirt:0.27.0
-
cpe:2.3:a:kubevirt:kubevirt:0.28.0
-
cpe:2.3:a:kubevirt:kubevirt:0.29.0
-
cpe:2.3:a:kubevirt:kubevirt:0.29.1
-
cpe:2.3:a:kubevirt:kubevirt:0.29.2
-
cpe:2.3:a:kubevirt:kubevirt:0.30.0
-
cpe:2.3:a:kubevirt:kubevirt:0.30.1
-
cpe:2.3:a:kubevirt:kubevirt:0.30.2
-
cpe:2.3:a:kubevirt:kubevirt:0.30.3
-
cpe:2.3:a:kubevirt:kubevirt:0.30.4
-
cpe:2.3:a:kubevirt:kubevirt:0.30.5
-
cpe:2.3:a:kubevirt:kubevirt:0.30.6
-
cpe:2.3:a:kubevirt:kubevirt:0.31.0
-
cpe:2.3:a:kubevirt:kubevirt:0.32.0
-
cpe:2.3:a:kubevirt:kubevirt:0.33.0
-
cpe:2.3:a:kubevirt:kubevirt:0.34.0