CVE-2024-5154
A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (“../“). This flaw allows the container to read and write to arbitrary files on the host system.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.1
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N
- EPSS probability
- 1.24%
- CWE
- CWE-22
- Published
- 2024-06-12
- Last modified
- 2026-08-21
Affected products
- Red Hat Red Hat OpenShift Container Platform 4.12
- Red Hat Red Hat OpenShift Container Platform 4.13
- Red Hat Red Hat OpenShift Container Platform 4.14
- Red Hat Red Hat OpenShift Container Platform 4.15
- Red Hat Red Hat OpenShift Container Platform 4.16
- Red Hat Red Hat OpenShift Container Platform 4.16
- Red Hat Red Hat OpenShift Container Platform 4.16
- Red Hat Red Hat OpenShift Container Platform 4.17
Weakness type
Related vulnerabilities
- CVE-2026-85706 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
- CVE-2026-78657 — SigmaForms Pro <= 1.4.11 - Unauthenticated Arbitrary File Deletion via Path Traversal in File Upload Field
- CVE-2026-61560 — @zereight/mcp-gitlab's unauthenticated arbitrary file read via `upload_markdown` enables PAT exfiltration and full account takeover
- CVE-2026-54617 — GravitLauncher: Unauthenticated path traversal in LaunchServer FileServerHandler
- CVE-2026-45140 — Chamilo LMS CStudio upload flow allows unauthenticated remote code execution
- CVE-2026-82100 — DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
- CVE-2026-54053 — Many Notes: Path Traversal via ZIP import allows arbitrary file write and stored XSS in other users' vaults
- CVE-2026-85661 — excel-mcp-server 0.1.8 Arbitrary File Read/Write via stdio mode