{"id":"CVE-2020-1701","aliases":["GHSA-849r-8wvp-4wwg","GO-2024-2765"],"url":"https://o3.security/vulnerability/CVE-2020-1701","summary":"Permissions bypass in KubeVirt","details":"A flaw was found in the KubeVirt main virt-handler versions before 0.26.0 regarding the access permissions of virt-handler. An attacker with access to create VMs could attach any secret within their namespace, allowing them to read the contents of that secret.","published":"2021-05-27T20:15:07.957Z","modified":"2026-07-09T00:06:26.089484Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Go","name":"kubevirt.io/kubevirt","fixedVersion":"0.26.0"}],"fix":null,"references":[{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1792092"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T00:06:26.089484Z"}}