Command Injection in CRI-O - CVE-2024-3154
Published: April 30, 2024
Vulnerability details
The vulnerability allows a remote user to execute arbitrary commands on the target system.
The vulnerability exists due to the systemd property injection. A remote administrator can pass specially crafted data to the application and execute arbitrary commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Guardium Data Security Center (GDSC)
openEuler
docker-runc
runc
cri-o (Red Hat package)
podman (Red Hat package)
openshift (Red Hat package)
Red Hat OpenShift Container Platform
IBM Cloud Pak for Business Automation
How to mitigate CVE-2024-3154
Guardium Data Security Center (GDSC) - update to 3.8.5
docker-runc - update to 1.1.3-25
runc - update to 1.1.3-26
cri-o (Red Hat package) - addressed in versions 1.27.6-2.rhaos4.14.gitb3bd0bf.el8, 1.27.6-2.rhaos4.14.gitb3bd0bf.el9
podman (Red Hat package) - addressed in versions 4.4.1-13.4.rhaos4.14.el8, 4.4.1-13.4.rhaos4.14.el9
Red Hat OpenShift Container Platform - addressed in versions 4.12.57, 4.13.43, 4.15.12, 4.15.15
openshift (Red Hat package) - addressed in versions 4.14.0-202404301807.p0.gfd36fb9.assembly.stream.el8, 4.14.0-202404301807.p0.gfd36fb9.assembly.stream.el9
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1
External References
- https://access.redhat.com/security/cve/CVE-2024-3154
- https://bugzilla.redhat.com/show_bug.cgi?id=2272532
- https://github.com/cri-o/cri-o/security/advisories/GHSA-2cgq-h8xw-2v5j
- https://github.com/opencontainers/runc/pull/4217
- https://github.com/opencontainers/runtime-spec/blob/main/features.md#unsafe-annotations-in-configjson
Related Security Bulletins
- Command Injection in CRI-O
- openEuler 22.03 LTS SP2 update for runc
- openEuler 22.03 LTS SP3 update for runc
- openEuler 22.03 LTS SP1 update for runc
- Command Injection in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14 packages
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM Guardium Data Security Center