Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-6476

Опубликовано: 09 янв. 2024
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A flaw was found in CRI-O that involves an experimental annotation leading to a container being unconfined. This may allow a pod to specify and get any amount of memory/cpu, circumventing the kubernetes scheduler and potentially resulting in a denial of service in the node.

Отчет

There are two main factors reduce the severity of this vulnerability to Moderate:

  • A potential attacker must already have valid credentials
  • The OpenShift environment must already be configured to use an experimental feature

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 3.11cri-oOut of support scope
Red Hat OpenShift Container Platform 4.13cri-oFixedRHSA-2024:019517.01.2024
Red Hat OpenShift Container Platform 4.14cri-oFixedRHSA-2024:020717.01.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2253994cri-o: Pods are able to break out of resource confinement on cgroupv2

EPSS

Процентиль: 39%
0.00168
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 1 года назад

A flaw was found in CRI-O that involves an experimental annotation leading to a container being unconfined. This may allow a pod to specify and get any amount of memory/cpu, circumventing the kubernetes scheduler and potentially resulting in a denial of service in the node.

CVSS3: 6.5
nvd
больше 1 года назад

A flaw was found in CRI-O that involves an experimental annotation leading to a container being unconfined. This may allow a pod to specify and get any amount of memory/cpu, circumventing the kubernetes scheduler and potentially resulting in a denial of service in the node.

CVSS3: 6.5
debian
больше 1 года назад

A flaw was found in CRI-O that involves an experimental annotation lea ...

CVSS3: 7.5
redos
около 1 года назад

Уязвимость Cri-o

CVSS3: 6.5
github
больше 1 года назад

CRI-O's pods can break out of resource confinement on cgroupv2

EPSS

Процентиль: 39%
0.00168
Низкий

6.5 Medium

CVSS3