GHSA-c5pj-mqfh-rvc3 – github.com/opencontainers/runc
Package
Manager: go
Name: github.com/opencontainers/runc
Vulnerable Version: <0
Severity
Level: High
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0: N/A
EPSS: N/A pctlN/A
Details
Withdrawn: Runc allows an arbitrary systemd property to be injected ## Withdrawn Advisory This advisory has been withdrawn because it was incorrectly attributed to runc. Please see the issue [here](https://github.com/opencontainers/runc/issues/4263) for more information. ## Original Description A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary annotation may perform an arbitrary action on the host system. This issue has its root in how runc handles Config Annotations lists.
Metadata
Created: 2024-04-26T06:30:34Z
Modified: 2024-06-05T18:30:34Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/04/GHSA-c5pj-mqfh-rvc3/GHSA-c5pj-mqfh-rvc3.json
CWE IDs: ["CWE-77"]
Alternative ID: N/A
Finding: N/A
Auto approve: 0