CVE-2022-1798 HIGH

CVE-2022-1798: Path Traversal vulnerability in Kubevirt

Vendor Google Llc
Product Kubevirt
Weakness CWE-20 · Input validation
Published September 15, 2022
Last update April 21, 2025

CVSS base score

8.7/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity Low

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:H

What the vulnerability does

01Description

A path traversal vulnerability in KubeVirt versions up to 0.56 (and 0.55.1) on all platforms allows a user able to configure the kubevirt to read arbitrary files on the host filesystem which are publicly readable or which are readable for UID 107 or GID 107. /proc/self/<> is not accessible.

Key dates

02Disclosure timeline

September 15, 2022 CVE published
April 21, 2025 Record updated