Impact
A path traversal flaw in KubeVirt’s virt-exportserver allows an attacker with namespace‑level privileges to create a symbolic link inside an exported Persistent Volume Claim that points outside the intended mount root. The exporter pod can resolve the link and read files on its own filesystem, exposing arbitrary sensitive content. This results in information disclosure.
Affected Systems
The vulnerability affects Red Hat OpenShift Virtualization 4, specifically the KubeVirt virt-exportserver component that runs inside the exporter pod. All deployments of this component are impacted unless software is updated to a version that contains the fix.
Risk and Exploitability
The flaw carries a CVSS score of 7.7, indicating a high‑severity risk. The EPSS score is not published, and it is not listed in the CISA KEV catalog, leaving the exact exploit probability unclear. However, because the attacker only requires namespace‑level access and the ability to write a symbolic link, the attack is realistic in many cluster configurations. The potential to read arbitrary files from the exporter pod’s filesystem elevates the risk to confidentiality and could support lateral movement if privileged data is exposed.
OpenCVE Enrichment