Dismissed
by @LeSuisse Activity log
- Created automatic suggestion
- @fricklerhandwerk accepted
- @fricklerhandwerk marked as untriaged
- @fricklerhandwerk accepted
- @LeSuisse dismissed
Cri-o: malicious container can create symlink on host
A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (“../“). This flaw allows the container to read and write to arbitrary files on the host system.
Affected products
cri-o
- <1.30.1
- <1.28.7
- *
- <1.29.5
rhcos
- *
conman
conmon
kernel
- *
openshift
- *
container-tools:rhel8/podman
Matching in nixpkgs
pkgs.cri-o
Open Container Initiative-based implementation of the Kubernetes Container Runtime Interface
Package maintainers
-
@saschagrunert Sascha Grunert <mail@saschagrunert.de>
-
@vdemeester Vincent Demeester <vincent@sbr.pm>