CVE-2019-3841: Kubevirt Containerized Data Importer
Medium severity, CVSS 6.8. EPSS: 0.5% chance of exploitation in the next 30 days.
Kubevirt/virt-cdi-importer, versions 1.4.0 to 1.5.3 inclusive, were reported to disable TLS certificate validation when importing data into PVCs from container registries. This could enable man-in-the-middle attacks between a container registry and the virt-cdi-component, leading to possible undetected tampering of trusted container image content.
Affected products
- Kubevirt Containerized Data Importer: from 1.4.0, up to and including 1.5.3
Published 2019-03-25. Last modified 2026-06-17.