The vendor explicitly identifies these products as affected by this CVE.
- cri-o as a component of Red Hat OpenShift Container Platform 3.11
- cri-o.src as a component of Red Hat OpenShift Container Platform 3.11
- Summary
- A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (“../“). This flaw allows the container to read and write to arbitrary files on the host system.
- Remediation
- For OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html
