github.com/cri-o/cri-o vulnerabilities
CVEs whose affected-version data names the github.com/cri-o/cri-o package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
5 CVEsRSS
CVE-2024-5154High· 8.1malicious container creates symlink "mtab" on the host External
malicious container creates symlink "mtab" on the host External
▾ Twilightcri-o · github.com/cri-o/cri-oEPSS 1.2%via OSV
CVE-2024-3154High· 7.2A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation
A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary annotation may perform an arbitrary action on the host system.
▾ Twilightcri-o · github.com/cri-o/cri-oEPSS 1.4%via NVD
CVE-2022-1708High· 7.5Node DOS by way of memory exhaustion through ExecSync request in CRI-O
Node DOS by way of memory exhaustion through ExecSync request in CRI-O
▾ Twilightcri-o · github.com/cri-o/cri-oEPSS 3.1%via OSV
CVE-2022-27652Medium· 4.8Incorrect Default Permissions in CRI-O
Incorrect Default Permissions in CRI-O
▾ Sunlitcri-o · github.com/cri-o/cri-oEPSS 0.25%via OSV
CVE-2022-0811High· 8.8PoCCode Injection in CRI-O
Code Injection in CRI-O
▾ Midnightcri-o · github.com/cri-o/cri-oEPSS 19%via OSV