Description
A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary annotation may perform an arbitrary action on the host system.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1060 | A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary annotation may perform an arbitrary action on the host system. |
Github GHSA |
GHSA-2cgq-h8xw-2v5j | CRI-O vulnerable to an arbitrary systemd property injection |
References
History
Wed, 27 Aug 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-11-20T07:17:45.415Z
Reserved: 2024-04-01T19:43:56.801Z
Link: CVE-2024-3154
Updated: 2024-08-01T20:05:07.032Z
Status : Deferred
Published: 2024-04-26T04:15:09.217
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-3154
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA