Skip to main content

Vendor/product archive

kubernetes / cri-o CVEs

Beta · best-effort

10 CVEs tagged to kubernetes / cri-o0 Critical, 6 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2022-4318

Published Sep 25, 2023

A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.

CVSS 7.8 · High

CVE-2022-2995

Published Sep 19, 2022

Incorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclosure or possible data modification if an attacker has direct…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-0811

Published Mar 16, 2022

A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime to a…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2018-1000400

Published May 18, 2018

Kubernetes CRI-O version prior to 1.9 contains a Privilege Context Switching Error (CWE-270) vulnerability in the handling of ambient capabilities that can result in containers ru…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1