Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-0750

Опубликовано: 22 янв. 2025
Источник: redhat
CVSS3: 6.6
EPSS Низкий

Описание

A vulnerability was found in CRI-O. A path traversal issue in the log management functions (UnMountPodLogs and LinkContainerLogs) may allow an attacker with permissions to create and delete Pods to unmount arbitrary host paths, leading to node-level denial of service by unmounting critical system directories.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4rhcosFix deferred
Red Hat OpenShift Container Platform 4.17cri-oFixedRHSA-2025:112211.02.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2339405cri-o: CRI-O Path Traversal in Log Handling Functions Allows Arbitrary Unmounting

EPSS

Процентиль: 19%
0.00061
Низкий

6.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.6
ubuntu
11 месяцев назад

A vulnerability was found in CRI-O. A path traversal issue in the log management functions (UnMountPodLogs and LinkContainerLogs) may allow an attacker with permissions to create and delete Pods to unmount arbitrary host paths, leading to node-level denial of service by unmounting critical system directories.

CVSS3: 6.6
nvd
11 месяцев назад

A vulnerability was found in CRI-O. A path traversal issue in the log management functions (UnMountPodLogs and LinkContainerLogs) may allow an attacker with permissions to create and delete Pods to unmount arbitrary host paths, leading to node-level denial of service by unmounting critical system directories.

CVSS3: 6.6
debian
11 месяцев назад

A vulnerability was found in CRI-O. A path traversal issue in the log ...

CVSS3: 6.6
github
11 месяцев назад

CRI-O Path Traversal vulnerability

suse-cvrf
11 месяцев назад

Security update for govulncheck-vulndb

EPSS

Процентиль: 19%
0.00061
Низкий

6.6 Medium

CVSS3