CVE-2022-0811
HIGH 9.0EPSS 19.0%
A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime to achieve a container escape and arbitrary code execution as root on the cluster node, where the malicious pod was deployed.
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 9.0 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C - EPSS
- 19.05% chance of exploitation in the next 30 days, 97th percentile
- Published
- 2022-03-16
- Updated
- 2024-08-02
Proof-of-concept exploits (3)
- spiarh/webhook-cve-2022-08118★ · 2022-03-21
- turbra/ocp-cr8escape0★ · 2022-03-17
- h4ckm310n/Container-Vulnerability-Exploit