Описание
A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary annotation may perform an arbitrary action on the host system.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift Container Platform 3.11 | cri-o | Not affected | ||
| Red Hat OpenShift Container Platform 4.12 | cri-o | Fixed | RHSA-2024:2784 | 16.05.2024 |
| Red Hat OpenShift Container Platform 4.13 | cri-o | Fixed | RHSA-2024:3496 | 05.06.2024 |
| Red Hat OpenShift Container Platform 4.14 | cri-o | Fixed | RHSA-2024:2672 | 09.05.2024 |
| Red Hat OpenShift Container Platform 4.15 | cri-o | Fixed | RHSA-2024:2669 | 09.05.2024 |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
7.2 High
CVSS3
Связанные уязвимости
A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary annotation may perform an arbitrary action on the host system.
A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary annotation may perform an arbitrary action on the host system.
A flaw was found in cri-o, where an arbitrary systemd property can be ...
EPSS
7.2 High
CVSS3