← Zurück zur CVE-Suche

CVE-2026-17527

containerized-data-importer

Beschreibung

In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only access to CDI resources, includes a rule granting create on the datavolumes/source subresource. CDI-s DataVolume clone authorization accepts this permission as sufficient to authorize cloning the contents of any PVC the caller can name, without requiring write access to the source namespace. A user or service account bound to the view role, commonly granted cluster-wide via ClusterRoleBinding, who also has ordinary write access (edit/admin) to any single namespace, can use this to exfiltrate the contents of any PVC in the cluster into a namespace they control, bypassing namespace isolation and the read-only guarantee of the view role.

CVSS 7.7EPSS 0.375%Risiko 0.8
Quelle öffnen
Veröffentlicht
2026-07-27 10:16:37
Betroffene Versionen
unknown
Typ
Kritische Software
Zuletzt geändert
2026-07-27 20:37:16
Vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N