VYPR
High severity8.1OSV Advisory· Published Jun 12, 2024· Updated Jun 17, 2026

CVE-2024-5154

CVE-2024-5154

Description

A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (“../“). This flaw allows the container to read and write to arbitrary files on the host system.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/cri-o/cri-oGo
>= 1.28.6, < 1.28.71.28.7
github.com/cri-o/cri-oGo
>= 1.29.4, < 1.29.51.29.5
github.com/cri-o/cri-oGo
>= 1.30.0, < 1.30.11.30.1

Affected products

11
  • Cri O/Cri OOSV4 versions
    v0.0.0, v0.1, v0.2, …+ 3 more
    • (no CPE)range: v0.0.0, v0.1, v0.2, …
    • cpe:2.3:a:kubernetes:cri-o:1.28.6:*:*:*:*:*:*:*
    • cpe:2.3:a:kubernetes:cri-o:1.29.4:*:*:*:*:*:*:*
    • cpe:2.3:a:kubernetes:cri-o:1.30.0:*:*:*:*:*:*:*
  • cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:openshift_container_platform:4.12:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:openshift_container_platform:4.13:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:openshift_container_platform:4.14:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:openshift_container_platform:4.15:*:*:*:*:*:*:*
  • ghsa-coords
    Range: >= 1.28.6, < 1.28.7

Patches

Vulnerability mechanics

References

12

News mentions

0

No linked articles in our index yet.