Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-5154


A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (“../“). This flaw allows the container to read and write to arbitrary files on the host system.


Published

2024-06-12T09:15:19.973

Last Modified

2025-06-23T14:15:26.073

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.1 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-22
  • Type: Secondary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application kubernetes cri-o 1.28.6 Yes
Application kubernetes cri-o 1.29.4 Yes
Application kubernetes cri-o 1.30.0 Yes
Application redhat openshift_container_platform 3.11 Yes
Application redhat openshift_container_platform 4.0 Yes
Application redhat openshift_container_platform 4.12 Yes
Application redhat openshift_container_platform 4.13 Yes
Application redhat openshift_container_platform 4.14 Yes
Application redhat openshift_container_platform 4.15 Yes
Operating System redhat enterprise_linux 8.0 No
Operating System redhat enterprise_linux 9.0 No

References