VYPR

containerized-data-importer

by Red Hat

CVEs (1)

  • CVE-2026-17527HigJul 27, 2026
    risk 0.50cvss 7.7epss 0.00

    In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only access to CDI resources, includes a rule granting create on the datavolumes/source subresource. CDI's DataVolume clone authorization accepts this permission as…