Cri O

Vendor:

First CVE: May 18, 2018 · Active for 8 years

10
Total CVEs
More Total CVEs than 89% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Cri O over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 18, 2018
8 years ago
Most Recent CVE
Jun 12, 2024
776 days ago

CVE Severity & Scoring

Cri O10 CVEs
All CVEs353,240 CVEs
MediumHigh
Attack Vector
Local4 (40.0%)
Network6 (60.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (80.0%)
High2 (20.0%)
Unknown0 (0.0%)
User Interaction
None9 (90.0%)
Unknown0 (0.0%)
Required1 (10.0%)
Privileges Required
Low8 (80.0%)
High1 (10.0%)
None1 (10.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime to ac
Mar 16, 20228.836NONO
Kubernetes CRI-O version prior to 1.9 contains a Privilege Context Switching Error (CWE-270) vulnerability in the handling of ambient capabilities that can result in containers run
May 18, 20188.827NONO
A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (“../“). This flaw allows the container to read a
Jun 12, 20248.124NONO
A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.
Sep 25, 20237.824NONO
Incorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclosure or possible data modification if an attacker has direct
Sep 19, 20227.124NONO
A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the Kube API. The ExecSync request runs commands in a container
Jun 7, 20227.523NONO
The version of cri-o as released for Red Hat OpenShift Container Platform 4.9.48, 4.10.31, and 4.11.6 via RHBA-2022:6316, RHBA-2022:6257, and RHBA-2022:6658, respectively, included
Sep 15, 20235.319NONO
A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers started
Apr 18, 20225.319NONO
A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup. This can result in container management (conmon) processes being killed
Nov 25, 20195.018NONO
An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from the list of "safe" sysctls specified for the cluster will be applied to the host
Feb 9, 20224.214NONO

Exploit Exposure

Signals from CVEs in this product scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (10 CVEs).

Media Mentions

Signals from CVEs in this product scope (10 CVEs).

Top CNAs Publishing CVEs For Cri O

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.30.018.11.2%00
1.29.418.11.2%00
1.28.618.11.2%00
1.25.017.10.4%00
1.24.017.52.8%00