EUVD-2024-1060
A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary annotation may perform an arbitrary action on the host system.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Not present in the current ENISA EUVD known-exploited dataset. This is not proof of no exploitation.
- ENISA score
- 7.2 · CVSS 3.1
- Advisory evidence
- No linked advisory details stored yet
