Root Node Volume Access Vulnerability Discovered in OpenShift Virtualization's HCP
CVE-2024-1725
Key Information:
- Status
- Vendor
- CVE Published:
- 7 March 2024
What is CVE-2024-1725?
A vulnerability exists within the kubevirt-csi component of OpenShift Virtualization's Hosted Control Plane, which may allow an authenticated attacker to gain unauthorized access to the root volume of HCP worker nodes. This is achieved through the creation of a tailored Persistent Volume that corresponds with the worker node's name. If exploited, this flaw could lead to significant security breaches, as it enables potential modification or access of sensitive information residing in the root volume. It is crucial for users to assess their deployments and apply necessary updates to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
