Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hp5j-2585-qx6g

Опубликовано: 28 янв. 2025
Источник: github
Github: Прошло ревью
CVSS3: 6.6

Описание

CRI-O Path Traversal vulnerability

A vulnerability was found in CRI-O. A path traversal issue in the log management functions (UnMountPodLogs and LinkContainerLogs) may allow an attacker with permissions to create and delete Pods to unmount arbitrary host paths, leading to node-level denial of service by unmounting critical system directories.

Пакеты

Наименование

github.com/cri-o/cri-o

go
Затронутые версииВерсия исправления

<= 1.33.0

Отсутствует

EPSS

Процентиль: 19%
0.00061
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.6
ubuntu
11 месяцев назад

A vulnerability was found in CRI-O. A path traversal issue in the log management functions (UnMountPodLogs and LinkContainerLogs) may allow an attacker with permissions to create and delete Pods to unmount arbitrary host paths, leading to node-level denial of service by unmounting critical system directories.

CVSS3: 6.6
redhat
11 месяцев назад

A vulnerability was found in CRI-O. A path traversal issue in the log management functions (UnMountPodLogs and LinkContainerLogs) may allow an attacker with permissions to create and delete Pods to unmount arbitrary host paths, leading to node-level denial of service by unmounting critical system directories.

CVSS3: 6.6
nvd
11 месяцев назад

A vulnerability was found in CRI-O. A path traversal issue in the log management functions (UnMountPodLogs and LinkContainerLogs) may allow an attacker with permissions to create and delete Pods to unmount arbitrary host paths, leading to node-level denial of service by unmounting critical system directories.

CVSS3: 6.6
debian
11 месяцев назад

A vulnerability was found in CRI-O. A path traversal issue in the log ...

suse-cvrf
11 месяцев назад

Security update for govulncheck-vulndb

EPSS

Процентиль: 19%
0.00061
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-22