Total vulnerabilities in the database
A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (“../“). This flaw allows the container to read and write to arbitrary files on the host system.
Software | From | Fixed in |
---|---|---|
![]() |
1.30.0 | 1.30.0.x |
![]() |
1.30.0 | 1.30.1 |
![]() |
1.29.4 | 1.29.4.x |
![]() |
1.29.4 | 1.29.5 |
![]() |
1.28.6 | 1.28.6.x |
![]() |
1.28.6 | 1.28.7 |
kubernetes / cri-o | 1.30.0 | 1.30.0.x |
kubernetes / cri-o | 1.29.4 | 1.29.4.x |
kubernetes / cri-o | 1.28.6 | 1.28.6.x |
redhat / openshift_container_platform | 3.11 | 3.11.x |
redhat / openshift_container_platform | 4.0 | 4.0.x |
redhat / openshift_container_platform | 4.12 | 4.12.x |
redhat / openshift_container_platform | 4.13 | 4.13.x |
redhat / openshift_container_platform | 4.14 | 4.14.x |
redhat / openshift_container_platform | 4.15 | 4.15.x |