| id: GO-2024-2816 |
| modules: |
| - module: kubevirt.io/kubevirt |
| unsupported_versions: |
| - last_affected: 1.2.0 |
| vulnerable_at: 1.2.1 |
| summary: kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt |
| cves: |
| - CVE-2024-33394 |
| ghsas: |
| - GHSA-4q63-mr2m-57hf |
| references: |
| - advisory: https://github.com/advisories/GHSA-4q63-mr2m-57hf |
| - advisory: https://nvd.nist.gov/vuln/detail/CVE-2024-33394 |
| - web: https://gist.github.com/HouqiyuA/1b75e23ece7ad98490aec1c887bdf49b |
| source: |
| id: GHSA-4q63-mr2m-57hf |
| created: 2024-06-04T14:27:47.602792-04:00 |
| review_status: UNREVIEWED |