← Späť na vyhľadávanie CVE

CVE-2026-17527

containerized-data-importer

Popis

In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only access to CDI resources, includes a rule granting create on the datavolumes/source subresource. CDI-s DataVolume clone authorization accepts this permission as sufficient to authorize cloning the contents of any PVC the caller can name, without requiring write access to the source namespace. A user or service account bound to the view role, commonly granted cluster-wide via ClusterRoleBinding, who also has ordinary write access (edit/admin) to any single namespace, can use this to exfiltrate the contents of any PVC in the cluster into a namespace they control, bypassing namespace isolation and the read-only guarantee of the view role.

CVSS 7.7EPSS 0.375%Riziko 0.8
Zobraziť zdroj
Zverejnené
2026-07-27 10:16:37
Dotknuté verzie
unknown
Typ
Kritický softvér
Posledná úprava
2026-07-27 20:37:16
Vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N