CVE-2024-5154: Kubernetes Cri-O
High severity, CVSS 8.1. EPSS: 1.2% chance of exploitation in the next 30 days.
A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (“../“). This flaw allows the container to read and write to arbitrary files on the host system.
Affected products
- Kubernetes Cri-O: version 1.28.6 only; version 1.29.4 only; version 1.30.0 only
- Red Hat Openshift Container Platform: version 3.11 only; version 4.0 only; version 4.12 only; version 4.13 only; version 4.14 only; version 4.15 only
Published 2024-06-12. Last modified 2026-08-21.