Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-6476

Опубликовано: 09 янв. 2024
Источник: nvd
CVSS3: 6.5
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in CRI-O that involves an experimental annotation leading to a container being unconfined. This may allow a pod to specify and get any amount of memory/cpu, circumventing the kubernetes scheduler and potentially resulting in a denial of service in the node.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

Одно из

cpe:2.3:a:redhat:openshift_container_platform:4.13:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.14:*:*:*:*:*:*:*

Одно из

cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

EPSS

Процентиль: 39%
0.00168
Низкий

6.5 Medium

CVSS3

7.5 High

CVSS3

Дефекты

CWE-770
CWE-770

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 1 года назад

A flaw was found in CRI-O that involves an experimental annotation leading to a container being unconfined. This may allow a pod to specify and get any amount of memory/cpu, circumventing the kubernetes scheduler and potentially resulting in a denial of service in the node.

CVSS3: 6.5
redhat
больше 1 года назад

A flaw was found in CRI-O that involves an experimental annotation leading to a container being unconfined. This may allow a pod to specify and get any amount of memory/cpu, circumventing the kubernetes scheduler and potentially resulting in a denial of service in the node.

CVSS3: 6.5
debian
больше 1 года назад

A flaw was found in CRI-O that involves an experimental annotation lea ...

CVSS3: 7.5
redos
около 1 года назад

Уязвимость Cri-o

CVSS3: 6.5
github
больше 1 года назад

CRI-O's pods can break out of resource confinement on cgroupv2

EPSS

Процентиль: 39%
0.00168
Низкий

6.5 Medium

CVSS3

7.5 High

CVSS3

Дефекты

CWE-770
CWE-770