Sensitive Information Disclosure in CRI-O Container Engine by Red Hat
CVE-2022-2995

7.1HIGH

Key Information:

Vendor
Kubernetes
Status
Vendor
CVE Published:
19 September 2022

Summary

The CRI-O container engine, developed by Red Hat, exhibits vulnerabilities in the handling of supplementary groups that could lead to unauthorized access to sensitive information or potential data manipulation. If an attacker gains direct access to a vulnerable container where supplementary groups dictate access permissions, they may execute arbitrary code within the container environment. This situation underscores the need for strict access controls and regular security assessments to mitigate risks associated with container deployments.

Affected Version(s)

cri-o cri-o 1.25.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
🍪 This website uses cookies, like every other website on the internet 😕 By using our website, you consent to the use of cookies.