CVE-2022-0811

Description from NVD

A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime to achieve a container escape and arbitrary code execution as root on the cluster node, where the malicious pod was deployed.

Information Acquisition Date:2022-03-31T16:40Z
CVSS 2.0: 9.0 HIGH CVSS 3.x: 8.8 HIGH

▼ CVSS3 Vec CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

▼ CVSS2 Vec AV:N/AC:L/Au:S/C:C/I:C/A:C

NVD References

 https://bugzilla.redhat.com/show_bug.cgi?id=2059475
     source:MISC
     tags:Issue Tracking    Third Party Advisory    
 https://github.com/cri-o/cri-o/security/advisories/GHSA-6x2m-w449-qwx7
     source:MISC
     tags:Third Party Advisory    

Refer to Information on External Sites

CVE InfomationExploits or more Infomation
mitreEXPLOIT DATABASE
NVD0day.today
vulmon.comgithub
CVE DetailsTwitter
JVN ENG JPN
Reconshell

Software Tag:



List of frequently cited URLs

URLNum of Times Referred to
https://www.reddit.com/r/netsec51
https://cvetrends.com48
http://cyberiqs.com/latestnews38
https://thehackernews.com/2022/03/new-vulnerability-in-cri-...11
http://ASP.NET4
https://github.com/cri-o/cri-o/security/advisories/GHSA-6x2...3
https://sysdig.com/blog/cve-2022-0811-cri-o3
https://opsmtrs.com/3IZx4mq3
https://blog.aquasec.com/cve-2022-0811-cri-o-vulnerability3
https://www.crowdstrike.com/blog/cr8escape-zero-day-vulnera...3
https://cloudsecurityalliance.org/articles/cr8escape-new-vu...3

Information from Twitter

User URL Info Source Date
LEOLAMCGILL14 https://github.com/cri-o/cri-o/security/advisories/GHSA-6x2... Source LEOLAMCGILL14    1626144266643996672 2023/02/16

List of frequently cited URLs

URLNum of Times Referred to
www.reddit.com51
cvetrends.com48
cyberiqs.com38
thehackernews.com11
ASP.NET4
github.com3
sysdig.com3
opsmtrs.com3
blog.aquasec.com3
www.crowdstrike.com3
cloudsecurityalliance.org3

Information from Twitter

User URL Info Source
LEOLAMCGILL14 github.com Show Tweet

GitHub Search Results: Up to 10
NameURL
spiarh/webhook-cve-2022-0811 https://github.com/spiarh/webhook-cve-2022-0811

GitHub Search Results: Up to 10
NameURL
spiarh/webhook-cve-2022-0811 github.com

2023/02/16 Score : 0
Added Har-sia Database : 2022/03/15
Last Modified : 2023/02/16
Highest Scored Date : 2022/03/17
Highest Score : 59