296,720
Total vulnerabilities in the database
A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (“../“). This flaw allows the container to read and write to arbitrary files on the host system.
| Software | From | Fixed in |
|---|---|---|
github.com/cri-o/cri-o
|
1.30.0 | 1.30.0.x |
github.com/cri-o/cri-o
|
1.30.0 | 1.30.1 |
github.com/cri-o/cri-o
|
1.29.4 | 1.29.4.x |
github.com/cri-o/cri-o
|
1.29.4 | 1.29.5 |
github.com/cri-o/cri-o
|
1.28.6 | 1.28.6.x |
github.com/cri-o/cri-o
|
1.28.6 | 1.28.7 |
| kubernetes / cri-o | 1.30.0 | 1.30.0.x |
| kubernetes / cri-o | 1.29.4 | 1.29.4.x |
| kubernetes / cri-o | 1.28.6 | 1.28.6.x |
| redhat / openshift_container_platform | 3.11 | 3.11.x |
| redhat / openshift_container_platform | 4.0 | 4.0.x |
| redhat / openshift_container_platform | 4.12 | 4.12.x |
| redhat / openshift_container_platform | 4.13 | 4.13.x |
| redhat / openshift_container_platform | 4.14 | 4.14.x |
| redhat / openshift_container_platform | 4.15 | 4.15.x |