Home/Product/kubernetes cri o
Product

kubernetes cri o

10 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-5154
all versions
A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal
8.1HIGH
CVE-2022-4318
all versions
A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially craft
7.8HIGH
CVE-2022-3466
all versions
The version of cri-o as released for Red Hat OpenShift Container Platform 4.9.48, 4.10.31, and 4.11.6 via RHBA-2022:6316, RHBA-202
4.8MEDIUM
CVE-2022-2995
all versions
Incorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclosure or pos
7.1HIGH
CVE-2022-1708
< 1.19.7
A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the Kube API.
7.5HIGH
CVE-2022-27652
all versions
A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found
5.3MEDIUM
CVE-2022-0811
>= 1.19.0 and < 1.19.6
A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Ku
8.8HIGH
CVE-2022-0532
<= 1.18
An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from the list of "safe" sysctls spe
4.2MEDIUM
CVE-2019-14891
< 1.16.1
A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup. This can result in con
5.0MEDIUM
CVE-2018-1000400
< 1.9.0
Kubernetes CRI-O version prior to 1.9 contains a Privilege Context Switching Error (CWE-270) vulnerability in the handling of ambi
8.8HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin