# CVE-2024-5154

## Summary

- **CVE ID:** CVE-2024-5154
- **Severity:** HIGH
- **CVSS Score:** 8.1 (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N)
- **CWE:** CWE-22
- **Published:** Jun 12, 2024
- **Last Modified:** Aug 21, 2026

## Description

A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (“../“). This flaw allows the container to read and write to arbitrary files on the host system.

## Affected Products

- Unknown product (1.30.0)
- Unknown product (1.29.4)
- Unknown product (1.28.6)
- Red Hat — Red Hat OpenShift Container Platform 4.12 (0:1.25.5-21.2.rhaos4.12.gita3eb75f.el8)
- Red Hat — Red Hat OpenShift Container Platform 4.13 (0:1.26.5-18.2.rhaos4.13.git2e90133.el8)
- Red Hat — Red Hat OpenShift Container Platform 4.14 (0:1.27.7-3.rhaos4.14.git674563e.el8)
- Red Hat — Red Hat OpenShift Container Platform 4.15 (0:1.28.7-2.rhaos4.15.git111aec5.el9)
- Red Hat — Red Hat OpenShift Container Platform 4.16 (0:1.29.5-7.rhaos4.16.git7db4ada.el8)
- Red Hat — Red Hat OpenShift Container Platform 4.16 (0:5.14.0-427.24.1.el9_4)
- Red Hat — Red Hat OpenShift Container Platform 4.16 (0:4.16.0-202406191607.p0.g58452d8.assembly.stream.el8)
- Red Hat — Red Hat OpenShift Container Platform 4.17 (417.94.202412040832-0)
- Red Hat — Red Hat OpenShift Container Platform 4.15 (0:1.28.7-2.rhaos4.15.git111aec5.el8)

## References

- [CNA](https://access.redhat.com/errata/RHSA-2024:10818)
- [CNA](https://access.redhat.com/errata/RHSA-2024:3676)
- [CNA](https://access.redhat.com/errata/RHSA-2024:3700)
- [CNA](https://access.redhat.com/errata/RHSA-2024:4008)
- [CNA](https://access.redhat.com/errata/RHSA-2024:4159)
- [CNA](https://access.redhat.com/errata/RHSA-2024:4486)
- [CNA](https://access.redhat.com/security/cve/CVE-2024-5154)
- [CNA](https://bugzilla.redhat.com/show_bug.cgi?id=2280190)
- [CNA](https://github.com/cri-o/cri-o/security/advisories/GHSA-j9hf-98c3-wrm8)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 1.24%
- **EPSS Percentile:** 67.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._