CVE-2019-10175 describes a flaw in the containerized-data-importer (CDI) in virt-cdi-cloner version 1.4, specifically impacting the host-assisted cloning feature. This vulnerability allows authenticated users to clone any Persistent Volume Claim (PVC) within the cluster into their own namespace, regardless of their permissions to the source PVC, leading to unauthorized data access. Rated 6.5 Medium, the attack requires low privileges and no user interaction, with a high impact on confidentiality. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.4.0CPE matchmatch criteria | cpe:2.3:a:kubevirt:containerized-data-importer:1.4.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.