CVE-2024-3154

A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary annotation may perform an arbitrary action on the host system.
Configurations

No configuration.

History

21 Nov 2024, 09:29

Type Values Removed Values Added
References () https://access.redhat.com/errata/RHSA-2024:2669 - () https://access.redhat.com/errata/RHSA-2024:2669 -
References () https://access.redhat.com/errata/RHSA-2024:2672 - () https://access.redhat.com/errata/RHSA-2024:2672 -
References () https://access.redhat.com/errata/RHSA-2024:2784 - () https://access.redhat.com/errata/RHSA-2024:2784 -
References () https://access.redhat.com/errata/RHSA-2024:3496 - () https://access.redhat.com/errata/RHSA-2024:3496 -
References () https://access.redhat.com/security/cve/CVE-2024-3154 - () https://access.redhat.com/security/cve/CVE-2024-3154 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=2272532 - () https://bugzilla.redhat.com/show_bug.cgi?id=2272532 -
References () https://github.com/cri-o/cri-o/security/advisories/GHSA-2cgq-h8xw-2v5j - () https://github.com/cri-o/cri-o/security/advisories/GHSA-2cgq-h8xw-2v5j -
References () https://github.com/opencontainers/runc/pull/4217 - () https://github.com/opencontainers/runc/pull/4217 -
References () https://github.com/opencontainers/runtime-spec/blob/main/features.md#unsafe-annotations-in-configjson - () https://github.com/opencontainers/runtime-spec/blob/main/features.md#unsafe-annotations-in-configjson -

05 Jun 2024, 17:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2024:3496 -

16 May 2024, 23:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2024:2784 -

09 May 2024, 22:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2024:2672 -

09 May 2024, 16:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2024:2669 -
Summary
  • (es) Se encontró una falla en cri-o, donde se puede inyectar una propiedad systemd arbitraria mediante una anotación Pod. Cualquier usuario que pueda crear un pod con una anotación arbitraria puede realizar una acción arbitraria en el sistema host.

26 Apr 2024, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-26 04:15

Updated : 2024-11-21 09:29


NVD link : CVE-2024-3154

Mitre link : CVE-2024-3154

CVE.ORG link : CVE-2024-3154


JSON object : View

Products Affected

No product.

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')