#VU88100 Trust Boundary Violation in Red Hat OpenShift Container Platform - CVE-2024-1725
Published: April 3, 2024
Red Hat OpenShift Container Platform
Red Hat Inc.
Description
The vulnerability allows a remote user to escalate privileges within the application.
The vulnerability exists due to an error in the kubevirt-csi component of OpenShift Virtualization's Hosted Control Plane (HCP). A remote user can gain access to the root HCP worker node's volume by creating a custom Persistent Volume that matches the name of a worker node.