CVE-2024-5154
CVE-2024-5154
highEPSS 1.2%
Description
Metrics
Severity
high
86.57
no public PoC known
8.1
Published
2024-06-12 09:15 UTC
CWE-22
Weakness classes (CWE)
CWE-22Base
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
cwe.mitre.org →
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-08-21 12:16 UTC· secalert@redhat.com
- Affected: …, Red Hat OpenShift Container Platform 4.12, Red Hat OpenShift Container Platform 4.13 (+10) → …, Red Hat OpenShift Container Platform 4.12, Red Hat OpenShift Container Platform 4.13 (+9)
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
kubernetes
cri-o
redhat
openshift_container_platform
References & sources
- https://github.com/cri-o/cri-o/security/advisories/GHSA-j9hf-98c3-wrm8web
- https://nvd.nist.gov/vuln/detail/CVE-2024-5154advisory
- https://access.redhat.com/errata/RHSA-2024:10818web
- https://access.redhat.com/errata/RHSA-2024:3676web
- https://access.redhat.com/errata/RHSA-2024:3700web
- https://access.redhat.com/errata/RHSA-2024:4008web
- https://access.redhat.com/errata/RHSA-2024:4159web
- https://access.redhat.com/errata/RHSA-2024:4486web
- https://access.redhat.com/security/cve/CVE-2024-5154web
- https://bugzilla.redhat.com/show_bug.cgi?id=2280190web
- https://github.com/cri-o/cri-opackage
- https://pkg.go.dev/vuln/GO-2024-2919web
IDCVE-2024-5154