Velero (prior to 1.4.3 and 1.5.2) in some instances doesn’t properly manage volume identifiers which may result in information leakage to unauthorized users.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Velero | Vmware | * | 1.4.3 (excluding) |
| Velero | Vmware | 1.5.0 (including) | 1.5.2 (excluding) |
References