CVE-2025-0750Path Traversal in Cri-o Cri-o

CWE-22Path Traversal6 documents5 sources
Severity
6.6MEDIUMNVD
EPSS
0.1%
top 83.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 28
Latest updateJan 29

Description

A vulnerability was found in CRI-O. A path traversal issue in the log management functions (UnMountPodLogs and LinkContainerLogs) may allow an attacker with permissions to create and delete Pods to unmount arbitrary host paths, leading to node-level denial of service by unmounting critical system directories.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:HExploitability: 1.8 | Impact: 4.7

Affected Packages1 packages

🔴Vulnerability Details

4
OSV
CRI-O Path Traversal vulnerability in github.com/cri-o/cri-o2025-01-29
CVEList
Cri-o: cri-o path traversal in log handling functions allows arbitrary unmounting2025-01-28
GHSA
CRI-O Path Traversal vulnerability2025-01-28
OSV
CRI-O Path Traversal vulnerability2025-01-28

📋Vendor Advisories

1
Red Hat
cri-o: CRI-O Path Traversal in Log Handling Functions Allows Arbitrary Unmounting2025-01-22
CVE-2025-0750 — Path Traversal in Cri-o Cri-o | cvebase