Total vulnerabilities in the database
A flaw was found in CRI-O that involves an experimental annotation leading to a container being unconfined. This may allow a pod to specify and get any amount of memory/cpu, circumventing the kubernetes scheduler and potentially resulting in a denial of service in the node.
Software | From | Fixed in |
---|---|---|
![]() |
1.29.0 | 1.29.0.x |
![]() |
1.29.0 | 1.29.1 |
![]() |
1.28.0 | 1.28.3 |
![]() |
- | 1.27.3 |
redhat / openshift_container_platform | 3.11 | 3.11.x |
redhat / openshift_container_platform | 4.13 | 4.13.x |
redhat / openshift_container_platform | 4.14 | 4.14.x |