« Volver al listado

CVE-2022-0811

Estado: ModificadaAlta (8.8)—

A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime to achieve a container escape and arbitrary code execution as root on the cluster node, where the malicious pod was deployed.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-0811",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:C/I:C/A:C",
          "authentication": "SINGLE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "CRI-O",
          "versions": [
            {
              "status": "affected",
              "version": "cri-o 1.24.0, cri-o 1.23.2, cri-o 1.22.3, cri-o 1.21.6, cri-o 1.20.7, cri-o 1.19.6"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-03-16T15:15:16.123",
  "references": [
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2059475",
      "tags": [
        "Issue Tracking",
        "Third Party Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://github.com/cri-o/cri-o/security/advisories/GHSA-6x2m-w449-qwx7",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2059475",
      "tags": [
        "Issue Tracking",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/cri-o/cri-o/security/advisories/GHSA-6x2m-w449-qwx7",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "secalert@redhat.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-94"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-94"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime to achieve a container escape and arbitrary code execution as root on the cluster node, where the malicious pod was deployed."
    },
    {
      "lang": "es",
      "value": "Se ha encontrado un fallo en CRI-O en la forma de establecer las opciones del kernel para un pod. Este problema permite a cualquier persona con derechos desplegar un pod en un clúster Kubernetes que usa el tiempo de ejecución de CRI-O para lograr un escape del contenedor y la ejecución de código arbitrario como root en el nodo del clúster, donde fue desplegado el pod malicioso"
    }
  ],
  "lastModified": "2026-06-17T04:21:17.997",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:kubernetes:cri-o:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "70F9AEC5-AB20-4E02-8562-B400B2F796DD",
              "versionEndExcluding": "1.19.6",
              "versionStartIncluding": "1.19.0"
            },
            {
              "criteria": "cpe:2.3:a:kubernetes:cri-o:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3EC80AA9-7E85-408A-B2E8-873F648933C4",
              "versionEndExcluding": "1.20.7",
              "versionStartIncluding": "1.20.0"
            },
            {
              "criteria": "cpe:2.3:a:kubernetes:cri-o:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "60F1AA21-C728-478B-B5B6-B76F06107069",
              "versionEndExcluding": "1.21.6",
              "versionStartIncluding": "1.21.0"
            },
            {
              "criteria": "cpe:2.3:a:kubernetes:cri-o:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B95404BE-E267-4DE9-9D66-7EB535D32DA1",
              "versionEndExcluding": "1.22.3",
              "versionStartIncluding": "1.22.0"
            },
            {
              "criteria": "cpe:2.3:a:kubernetes:cri-o:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B2E27FBE-1FEE-496C-A677-FEBA235F4380",
              "versionEndExcluding": "1.23.2",
              "versionStartIncluding": "1.23.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}