Cri O
Vendor:
First CVE: May 18, 2018 · Active for 8 years
10
Total CVEs
More Total CVEs than 89% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Cri O over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 18, 2018
8 years ago
Most Recent CVE
Jun 12, 2024
776 days ago
CVE Severity & Scoring
Cri O10 CVEs
40%
60%
All CVEs353,240 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local4 (40.0%)
Network6 (60.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (80.0%)
High2 (20.0%)
Unknown0 (0.0%)
User Interaction
None9 (90.0%)
Unknown0 (0.0%)
Required1 (10.0%)
Privileges Required
Low8 (80.0%)
High1 (10.0%)
None1 (10.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0811HIGH A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime to ac | Mar 16, 2022 | 8.8 | 36 | NO | NO |
CVE-2018-1000400HIGH Kubernetes CRI-O version prior to 1.9 contains a Privilege Context Switching Error (CWE-270) vulnerability in the handling of ambient capabilities that can result in containers run | May 18, 2018 | 8.8 | 27 | NO | NO |
CVE-2024-5154HIGH A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (“../“). This flaw allows the container to read a | Jun 12, 2024 | 8.1 | 24 | NO | NO |
CVE-2022-4318HIGH A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable. | Sep 25, 2023 | 7.8 | 24 | NO | NO |
CVE-2022-2995HIGH Incorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclosure or possible data modification if an attacker has direct | Sep 19, 2022 | 7.1 | 24 | NO | NO |
CVE-2022-1708HIGH A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the Kube API. The ExecSync request runs commands in a container | Jun 7, 2022 | 7.5 | 23 | NO | NO |
CVE-2022-3466MEDIUM The version of cri-o as released for Red Hat OpenShift Container Platform 4.9.48, 4.10.31, and 4.11.6 via RHBA-2022:6316, RHBA-2022:6257, and RHBA-2022:6658, respectively, included | Sep 15, 2023 | 5.3 | 19 | NO | NO |
CVE-2022-27652MEDIUM A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers started | Apr 18, 2022 | 5.3 | 19 | NO | NO |
CVE-2019-14891MEDIUM A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup. This can result in container management (conmon) processes being killed | Nov 25, 2019 | 5.0 | 18 | NO | NO |
CVE-2022-0532MEDIUM An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from the list of "safe" sysctls specified for the cluster will be applied to the host | Feb 9, 2022 | 4.2 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Cri O
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.30.0 | 1 | 8.1 | 1.2% | 0 | 0 |
| 1.29.4 | 1 | 8.1 | 1.2% | 0 | 0 |
| 1.28.6 | 1 | 8.1 | 1.2% | 0 | 0 |
| 1.25.0 | 1 | 7.1 | 0.4% | 0 | 0 |
| 1.24.0 | 1 | 7.5 | 2.8% | 0 | 0 |