Database/Container, Kubernetes & orchestration

KubeVirt CDI: PVCs can be cloned from unauthorized namespaces via DataImportCron
CVSS 8.5CVE-2025-14459Container, Kubernetes & orchestrationcurated
Impact
PVCs can be cloned from unauthorized namespaces via DataImportCron; cross-tenant data theft
Who can reach it
Cluster user with namespace access
What to do
Upgrade CDI
References
Related entries
- Helm: Crafted Chart.yaml plus a symlinked Chart.lock gives local code execution when dependencies are updatedCVE-2025-53547 · HelmHigh
- Argo Workflows (workflow-controller, artifact repository credential logging): Workflow-controller writes artifactCVE-2025-62157 · Argo Workflows (workflow-controller, artifact repository credential logging)High
- KubeVirt: hostDisk feature mounts host files into a VM with insufficient restrictionCVE-2025-64324 · KubeVirtHigh
- Contrast initializer: regression re-exposes workload secrets by logging the full NewMeshCert responseCVE-2025-71423 · Contrast initializer (NewMeshCert response logged at INFO, versions 1.9.0-1.12.2)High
- Contrast initializer: workload secrets logged to Kubernetes pod logs at the default log levelCVE-2025-71425 · Contrast initializer (workload secret written to stderr at default log level)High
- LXD: crafted image templates escape the instance template directory and read or create host filesCVE-2026-16033 · LXD (image metadata template handling, QEMU/VM driver paths)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.