Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from the list of "safe" sysctls specified for the cluster will be applied to the host if an attacker is able to create a pod with a hostIPC and hostNetwork kernel namespace.
CVSS Information
N/A
Vulnerability Type
关键资源的不正确权限授予
Vulnerability Title
CRI-O 安全漏洞
Vulnerability Description
cri-o是一款用于Kubernetes系统的轻量级容器运行时环境。 CRI-O 存在安全漏洞,攻击者可利用该漏洞能够创建一个带有hostIPC和hostNetwork内核命名空间的pod。
CVSS Information
N/A
Vulnerability Type
N/A