CVE-2022-0811
Severity CVSS v4.0:
Pending analysis
Type:
CWE-94
Code Injection
Publication date:
16/03/2022
Last modified:
28/03/2022
Description
A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime to achieve a container escape and arbitrary code execution as root on the cluster node, where the malicious pod was deployed.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
9.00
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:kubernetes:cri-o:*:*:*:*:*:*:*:* | 1.19.0 (including) | 1.19.6 (excluding) |
| cpe:2.3:a:kubernetes:cri-o:*:*:*:*:*:*:*:* | 1.20.0 (including) | 1.20.7 (excluding) |
| cpe:2.3:a:kubernetes:cri-o:*:*:*:*:*:*:*:* | 1.21.0 (including) | 1.21.6 (excluding) |
| cpe:2.3:a:kubernetes:cri-o:*:*:*:*:*:*:*:* | 1.22.0 (including) | 1.22.3 (excluding) |
| cpe:2.3:a:kubernetes:cri-o:*:*:*:*:*:*:*:* | 1.23.0 (including) | 1.23.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



