[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250038

 
 

909

 
 

195843

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2024-3154Date: (C)2024-04-26   (M)2024-05-10


A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary annotation may perform an arbitrary action on the host system.

Reference:
RHBZ#2272532
RHSA-2024:2669
RHSA-2024:2672
https://access.redhat.com/security/cve/CVE-2024-3154
https://github.com/cri-o/cri-o/security/advisories/GHSA-2cgq-h8xw-2v5j
https://github.com/opencontainers/runc/pull/4217
https://github.com/opencontainers/runtime-spec/blob/main/features.md#unsafe-annotations-in-configjson

CWE    1
CWE-77
XCCDF    1

© SecPod Technologies