Lucene search

K
osvGoogleOSV:CVE-2022-1798
HistorySep 15, 2022 - 4:15 p.m.

CVE-2022-1798

2022-09-1516:15:10
Google
osv.dev
6
kubevirt
path traversal
vulnerability
host filesystem
software

6.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

26.5%

A path traversal vulnerability in KubeVirt versions up to 0.56 (and 0.55.1) on all platforms allows a user able to configure the kubevirt to read arbitrary files on the host filesystem which are publicly readable or which are readable for UID 107 or GID 107. /proc/self/<> is not accessible.

6.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

26.5%