VDB
BDU%3A2024-04923
BDU%3A2024-04923
PUBLISHED
CVSS 8.100000381469727 HIGH
Уязвимость прикладного программного интерфейса CRI-O Container Engine программного средства управления кластерами виртуальных машин Kubernetes, позволяющая нарушителю читать и записывать произвольные файлы в хост-системе
Risk Scores
CVSS 3.1
8.100000381469727
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4.16 | 0:4.16.0-202406191607.p0.g58452d8.assembly.stream.el8 |
| Red Hat | Red Hat OpenShift Container Platform 4.16 | 0:5.14.0-427.24.1.el9_4 |
| Red Hat | Red Hat OpenShift Container Platform 4.16 | 0:1.29.5-7.rhaos4.16.git7db4ada.el8 |
| Red Hat | Red Hat OpenShift Container Platform 4.17 | 417.94.202412040832-0 |
| Red Hat | Red Hat Enterprise Linux 8 | |
| Red Hat | Red Hat OpenShift Container Platform 4.14 | 0:1.27.7-3.rhaos4.14.git674563e.el8 |
| Red Hat | Red Hat OpenShift Container Platform 4.13 | 0:1.26.5-18.2.rhaos4.13.git2e90133.el8 |
| Red Hat | Red Hat Enterprise Linux 9 | |
| ООО «Ред Софт», Сообщество свободного программного обеспечения | РЕД ОС (запись в едином реестре российских программ №3751), CRI-O | |
| 1.30.0, 1.28.6, 1.29.4 | ||
| Red Hat | Red Hat OpenShift Container Platform 4.15 | 0:1.28.7-2.rhaos4.15.git111aec5.el8 |
| Red Hat | Red Hat OpenShift Container Platform 4.12 | 0:1.25.5-21.2.rhaos4.12.gita3eb75f.el8 |
| Red Hat | Red Hat OpenShift Container Platform 3.11 |
Timeline
- Jun 12, 2024 CVE Published
- Jul 2, 2024 CVE Updated
- Sep 3, 2026 Distribution Patch
- Sep 3, 2026 Distribution Patch
- Sep 3, 2026 Security Advisory
- Sep 3, 2026 Security Advisory
- Sep 3, 2026 Distribution Patch
- Sep 3, 2026 Distribution Patch
- Sep 3, 2026 Distribution Patch
- Sep 3, 2026 Distribution Patch
- Sep 3, 2026 Security Advisory
- Sep 3, 2026 Security Advisory
References
- RHSA-2024:10818 vendor-advisory
- RHSA-2024:4159 vendor-advisory
- RHSA-2024:3676 vendor-advisory
- RHSA-2024:3700 vendor-advisory
- RHSA-2024:4008 vendor-advisory
- RHSA-2024:4486 vendor-advisory
- https://access.redhat.com/security/cve/CVE-2024-5154 vdb
- RHBZ#2280190 issue
- https://github.com/cri-o/cri-o/security/advisories/GHSA-j9hf-98c3-wrm8 advisory
- https://redos.red-soft.ru/support/secure/ url
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ advisory