kubev2v/assisted-migration-agent

kubev2v/assisted-migration-agent

Releases4
Frequency1 week 4 days
Last Release
Stars1
A self-contained agent that discovers and assesses VMware environments for migration to OpenShift Virtualization.

CVE History

CVEPublishedCVSS v3CVSS v2
9.3 CRITICAL

A flaw was found in assisted-migration-agent. The application hardcodes insecure Transport Layer Security (TLS) connections when communicating with vCenter. This vulnerability allows a Man-in-the-Middle (MITM) attacker to intercept and harvest vCenter administrator credentials. This can lead to unauthorized access to vCenter.

9.6 CRITICAL

A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the same local area network (LAN), can exploit a path traversal vulnerability. By crafting a specially designed gzipped tarball, the attacker can bypass security checks and write arbitrary files to the system. This could ultimately lead to the execution of unauthorized code on the appliance.