CVE-2024-31419
Cnv: information disclosure through the usage of vm-dump-metrics
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An information disclosure flaw was found in OpenShift Virtualization. The DownwardMetrics feature was introduced to expose host metrics to virtual machine guests and is enabled by default. This issue could expose limited host metrics of a node to any guest in any namespace without being explicitly enabled by an administrator.
Se encontró una falla de divulgación de información en OpenShift Virtualization. La función DownwardMetrics se introdujo para exponer las métricas del host a las máquinas virtuales invitadas y está habilitada de forma predeterminada. Este problema podría exponer métricas de host limitadas de un nodo a cualquier invitado en cualquier espacio de nombres sin que un administrador lo habilite explícitamente.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-04-03 CVE Reserved
- 2024-04-03 CVE Published
- 2024-04-04 EPSS Updated
- 2024-11-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://access.redhat.com/security/cve/CVE-2024-31419 | Vdb Entry | |
https://bugzilla.redhat.com/show_bug.cgi?id=2272948 | Issue Tracking |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Redhat Search vendor "Redhat" | Container Native Virtualization Search vendor "Redhat" for product "Container Native Virtualization" | * | - |
Affected
|