CVE-2024-5154: Kubernetes Cri-O

High severity, CVSS 8.1. EPSS: 1.2% chance of exploitation in the next 30 days.

A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (“../“). This flaw allows the container to read and write to arbitrary files on the host system.

Affected products

  • Kubernetes Cri-O: version 1.28.6 only; version 1.29.4 only; version 1.30.0 only
  • Red Hat Openshift Container Platform: version 3.11 only; version 4.0 only; version 4.12 only; version 4.13 only; version 4.14 only; version 4.15 only

Published 2024-06-12. Last modified 2026-08-21.