A vulnerability was found in CRI-O. A path traversal issue in the log management functions (UnMountPodLogs and LinkContainerLogs) may allow an attacker with permissions to create and delete Pods to unmount arbitrary host paths, leading to node-level denial of service by unmounting critical system directories.
{ "nvd_published_at": "2025-01-28T10:15:09Z", "github_reviewed": true, "github_reviewed_at": "2025-01-28T19:15:28Z", "severity": "MODERATE", "cwe_ids": [ "CWE-22" ] }