A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary annotation may perform an arbitrary action on the host system.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-3154.json"