← לוח פגיעויות

CVE-2024-5154

גבוהה 8.1

תיאור (מקור, אנגלית)

A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (“../“). This flaw allows the container to read and write to arbitrary files on the host system.

מדדים

CVSS 3.1
8.1 (HIGH) מקור הציון: CNA CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N
EPSS — סבירות ניצול
1% (אחוזון 100) נכון ל-18/9/2026
CWE
CWE-22

מוצרים מושפעים

kubernetes: cri-o; redhat: openshift container platform; redhat: enterprise linux

קישורים