FlawAtlas
Search the atlas
CVE-2024-33394 Moderate

kubevirt allows a local attacker to execute arbitrary code via a crafted command

An issue in kubevirt kubevirt v1.2.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.

Exploit probability 0.3%
Published May 2, 2024
Required by Not available
Last source change June 20, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

158 explicit affected versions

Go kubevirt.io/kubevirt
Go kubevirt.io/kubevirt

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2024-33394

An issue in kubevirt kubevirt v1.2.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.

View original source
Open Source Vulnerabilities GO-2024-2816

kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt

View original source
Open Source Vulnerabilities GHSA-4q63-mr2m-57hf

An issue in kubevirt kubevirt v1.2.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.

View original source

05 / REFERENCES

Further evidence