A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (“../“). This flaw allows the container to read and write to arbitrary files on the host system.
2024-06-12T09:15:19.973
2025-06-23T14:15:26.073
Modified
CVSSv3.1: 8.1 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | kubernetes | cri-o | 1.28.6 | Yes |
Application | kubernetes | cri-o | 1.29.4 | Yes |
Application | kubernetes | cri-o | 1.30.0 | Yes |
Application | redhat | openshift_container_platform | 3.11 | Yes |
Application | redhat | openshift_container_platform | 4.0 | Yes |
Application | redhat | openshift_container_platform | 4.12 | Yes |
Application | redhat | openshift_container_platform | 4.13 | Yes |
Application | redhat | openshift_container_platform | 4.14 | Yes |
Application | redhat | openshift_container_platform | 4.15 | Yes |
Operating System | redhat | enterprise_linux | 8.0 | No |
Operating System | redhat | enterprise_linux | 9.0 | No |