CVE-2024-3154

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
26/04/2024
Last modified:
15/04/2026

Description

A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary annotation may perform an arbitrary action on the host system.