cve/2024/CVE-2024-3154.md
2024-06-18 02:51:15 +02:00

1.4 KiB

CVE-2024-3154

Description

A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary annotation may perform an arbitrary action on the host system.

POC

Reference

Github