← Retour à la recherche de CVE

CVE-2026-17527

containerized-data-importer

Description

In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only access to CDI resources, includes a rule granting create on the datavolumes/source subresource. CDI-s DataVolume clone authorization accepts this permission as sufficient to authorize cloning the contents of any PVC the caller can name, without requiring write access to the source namespace. A user or service account bound to the view role, commonly granted cluster-wide via ClusterRoleBinding, who also has ordinary write access (edit/admin) to any single namespace, can use this to exfiltrate the contents of any PVC in the cluster into a namespace they control, bypassing namespace isolation and the read-only guarantee of the view role.

CVSS 7.7EPSS 0.375%Risque 0.8
Voir la source
Publication
2026-07-27 10:16:37
Versions concernées
unknown
Type
Logiciel critique
Dernière modification
2026-07-27 20:37:16
Vecteur
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N