CRI-O是一款用于Kubernetes系统的轻量级容器运行时环境。 CRI-O 存在安全漏洞,该漏洞源于其允许具有可继承文件功能的程序访问权的攻击者在运行execve(2)时将这些功能提升到允许的集合。以下版本受到影响:基于Red Hat OpenShift Container Platform 4.9.48版本、4.10.31版本和4.11.6版本的cri-o。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4.12 | 0:1.25.1-5.rhaos4.12.git6005903.el9 ~ * |
cpe:/a:redhat:openshift:4.12::el8
|
|
| Red Hat | Red Hat OpenShift Container Platform 3.11 | - |
cpe:/a:redhat:openshift:3.11
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-0923 | 8.8 HIGH | Odh-notebook-controller-container: missing authorization allows for file contents disclosu |
| CVE-2023-4959 | 6.5 MEDIUM | Quay: cross-site request forgery (csrf) on config-editor page |
No comments yet