CVE-2024-31419

An information disclosure flaw was found in OpenShift Virtualization. The DownwardMetrics feature was introduced to expose host metrics to virtual machine guests and is enabled by default. This issue could expose limited host metrics of a node to any guest in any namespace without being explicitly enabled by an administrator.
Configurations

No configuration.

History

21 Nov 2024, 09:13

Type Values Removed Values Added
References () https://access.redhat.com/security/cve/CVE-2024-31419 - () https://access.redhat.com/security/cve/CVE-2024-31419 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=2272948 - () https://bugzilla.redhat.com/show_bug.cgi?id=2272948 -
Summary
  • (es) Se encontró una falla de divulgación de información en OpenShift Virtualization. La función DownwardMetrics se introdujo para exponer las métricas del host a las máquinas virtuales invitadas y está habilitada de forma predeterminada. Este problema podría exponer métricas de host limitadas de un nodo a cualquier invitado en cualquier espacio de nombres sin que un administrador lo habilite explícitamente.

03 Apr 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-03 14:15

Updated : 2024-11-21 09:13


NVD link : CVE-2024-31419

Mitre link : CVE-2024-31419

CVE.ORG link : CVE-2024-31419


JSON object : View

Products Affected

No product.

CWE
CWE-497

Exposure of Sensitive System Information to an Unauthorized Control Sphere