{"id":"CVE-2024-33394","aliases":["GHSA-4q63-mr2m-57hf","GO-2024-2816"],"title":"kubevirt allows a local attacker to execute arbitrary code via a crafted command ","summary":"kubevirt allows a local attacker to execute arbitrary code via a crafted command ","severity":"medium","cvss":5.9,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","vendor":"kubevirt","product":"kubevirt.io/kubevirt","ecosystem":"go","affected":["kubevirt.io/kubevirt <= 1.2.0"],"published":"2024-05-02","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:50:13.161569840Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-4q63-mr2m-57hf","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-33394"},{"url":"https://gist.github.com/HouqiyuA/1b75e23ece7ad98490aec1c887bdf49b"},{"url":"https://github.com/kubevirt/kubevirt"}],"tags":["osv","go"],"epss":0.00327,"epssPercentile":0.2605,"ingestedAt":"2026-09-12T03:13:01.753Z","slug":"CVE-2024-33394","body":"## Overview\n\nAn issue in kubevirt kubevirt v1.2.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.\n\n## Affected packages\n\n- `kubevirt.io/kubevirt <= 1.2.0`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":33,"depthScoreParts":{"impact":32.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}