A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary annotation may perform an arbitrary action on the host system.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/cri-o/cri-o(Go) | 1.29.0 | 1.29.4 | N/A |
| github.com/cri-o/cri-o(Go) | 1.28.0 | 1.28.6 | N/A |
| github.com/cri-o/cri-o(Go) | 0 | 1.27.6 | N/A |
CVSS Metrics