Sploitus

CVE-2024-5154

No indexed exploits for CVE-2024-5154 yet

A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (β€œ../β€œ). This flaw allows the container to read and write to arbitrary files on the host system.

Affected products
Alt Linux, Red Os, Cri-O
Kubernetes Cri-o
= 1.28.6, 1.29.4, 1.30.0
Fix
Available
CVSS 3.1
8.1 HIGH
EPSS
1.2% (66th percentile)
Weakness
CWE-22
NVD status
Modified
Published
2024-06-12

Workaround

There is no mitigation available for this vulnerability, a package update is required.

CVE-2024-5154 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2024-5154 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2024-5154 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows β€” not that no exploit exists.