Description
A flaw was found in KubeVirt Containerized Data Importer (CDI). This vulnerability allows a user to clone PersistentVolumeClaims (PVCs) from unauthorized namespaces, resulting in unauthorized access to data via the DataImportCron PVC source mechanism.
Problem types
Authorization Bypass Through User-Controlled Key
Product status
v4.19.17-5 (rpm) before *
v4.19.17-5 (rpm) before *
v4.19.17-5 (rpm) before *
v4.19.17-5 (rpm) before *
v4.19.17-5 (rpm) before *
v4.19.17-4 (rpm) before *
v4.19.17-3 (rpm) before *
v4.19.17.rhel9-82 (rpm) before *
v4.19.17-4 (rpm) before *
v4.19.17-4 (rpm) before *
v4.19.17-4 (rpm) before *
v4.19.17-7 (rpm) before *
v4.19.17-7 (rpm) before *
v4.19.17-5 (rpm) before *
v4.19.17-5 (rpm) before *
v4.19.17-5 (rpm) before *
v4.19.17-6 (rpm) before *
v4.19.17-5 (rpm) before *
v4.19.17-85 (rpm) before *
v4.19.17-5 (rpm) before *
v4.19.17-5 (rpm) before *
v4.19.17-5 (rpm) before *
v4.19.17-9 (rpm) before *
v4.19.17-5 (rpm) before *
v4.19.17-5 (rpm) before *
v4.19.17-11 (rpm) before *
v4.19.17-5 (rpm) before *
v4.19.17-9 (rpm) before *
v4.19.17-5 (rpm) before *
v4.19.17-19 (rpm) before *
v4.19.17-5 (rpm) before *
v4.19.17-9 (rpm) before *
v4.19.17-9 (rpm) before *
v4.19.17-9 (rpm) before *
v4.19.17-88 (rpm) before *
v4.19.17-9 (rpm) before *
v4.19.17-8 (rpm) before *
v4.19.17-8 (rpm) before *
v4.19.17-8 (rpm) before *
v4.19.17-7 (rpm) before *
v4.19.17-7 (rpm) before *
v4.19.17-7 (rpm) before *
v4.19.17-8 (rpm) before *
v4.19.17-8 (rpm) before *
v4.19.17-9 (rpm) before *
v4.19.17-9 (rpm) before *
v4.19.17-9 (rpm) before *
v4.19.17-9 (rpm) before *
v4.19.17-4 (rpm) before *
v4.19.17-9 (rpm) before *
v4.19.17-12 (rpm) before *
v4.19.17-5 (rpm) before *
v4.19.17-5 (rpm) before *
v4.19.17-5 (rpm) before *
Timeline
| 2025-12-10: | Reported to Red Hat. |
| 2026-01-08: | Made public. |
References
access.redhat.com/errata/RHSA-2026:0950 (RHSA-2026:0950)
access.redhat.com/security/cve/CVE-2025-14459
bugzilla.redhat.com/show_bug.cgi?id=2420938 (RHBZ#2420938)