Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2022-0811 PoC — cri-o 代码注入漏洞

Source
Associated Vulnerability
Title: cri-o 代码注入漏洞 (CVE-2022-0811)
Description:A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime to achieve a container escape and arbitrary code execution as root on the cluster node, where the malicious pod was deployed.
Description
Simple webhook to block exploitation of CVE-2022-0811
Readme
# webhook-cve-2022-0811

This is a really simple webhook that just blocks pod creation if malicious
sysctl values are configured.

## Build

```bash
go test
CGO_ENABLED=0 GOOS=linux GOARCH=amd64 GO111MODULE=on go build
```

## Build image an deploy in Minikube

Start minikube:

```bash
minikube start
minikube addons enable registry
```

Build:

```bash
podman build -t localhost:5000/webhook-cve-2022-0811:latest .
podman push --tls-verify=false "$(minikube ip):5000/webhook-cve-2022-0811:latest"
```

Deploy:

```bash
cd kustomize/
kustomize build | kubectl apply -f -
```

## Test

Create the following pod:

```yaml
apiVersion: v1
kind: Pod
metadata:
  name: sysctl-set
  namespace: default
spec:
  securityContext:
   sysctls:
   - name: kernel.shm_rmid_forced
     value: "1+kernel.core_pattern"
  containers:
  - name: test
    image: k8s.gcr.io/pause:3.2
```
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →