CVE-2024-5154
12.06.2024, 09:15
A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (../). This flaw allows the container to read and write to arbitrary files on the host system.
Vendor | Product | Version |
---|---|---|
kubernetes | cri-o | 1.28.6 |
kubernetes | cri-o | 1.29.4 |
kubernetes | cri-o | 1.30.0 |
redhat | openshift_container_platform | 3.11 |
redhat | openshift_container_platform | 4.0 |
redhat | openshift_container_platform | 4.12 |
redhat | openshift_container_platform | 4.13 |
redhat | openshift_container_platform | 4.14 |
redhat | openshift_container_platform | 4.15 |
𝑥
= Vulnerable software versions
References