Security Advisory

CVE-2024-3154

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-04-26 03:12:38
Last updated 2025-11-20 07:17:45
Assigner redhat
State PUBLISHED

Description

A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary annotation may perform an arbitrary action on the host system.