An information disclosure flaw was found in OpenShift Virtualization. The DownwardMetrics feature was introduced to expose host metrics to virtual machine guests and is enabled by default. This issue could expose limited host metrics of a node to any guest in any namespace without being explicitly enabled by an administrator.
History

Wed, 06 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2024-04-03T14:00:04.329Z

Updated: 2024-11-06T14:56:55.548Z

Reserved: 2024-04-03T12:10:43.208Z

Link: CVE-2024-31419

cve-icon Vulnrichment

Updated: 2024-08-02T01:52:56.894Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-04-03T14:15:17.787

Modified: 2024-11-21T09:13:29.700

Link: CVE-2024-31419

cve-icon Redhat

Severity : Low

Publid Date: 2024-04-03T00:00:00Z

Links: CVE-2024-31419 - Bugzilla