Executive brief
On a compromised node, the virt-handler service account can be used to modify all node specs
Affected products
- Go kubevirt.io/kubevirt
Junglewise Threat Intelligence
CVE-2023-26484 · Severity: low · CVSS 3.1 · Published 2023-03-16
Technologies: kubevirt.io/kubevirt (Go). Vendors: Go.
On a compromised node, the virt-handler service account can be used to modify all node specs