← Vulnerability feed

Vulnerability record · CVE-2022-2995 · published 19 September 2022

CVE-2022-2995: Kubernetes cri-o improper access control vulnerability

Kubernetes · Cri O

Incorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.

7.1 CVSS 3.1 High EPSS 0.39% · top 69.9% CWE-284 · Improper access controlCWE-732 · Incorrect permission assignment
7.1CVSS 3.1 base score
0.39%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Incorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-2995 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2022-0811Kubernetes cri-o code injection vulnerabilityA flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster th…EPSS 19%8.8CVE-2018-1000400Kubernetes cri-o improper privilege management vulnerabilityKubernetes CRI-O version prior to 1.9 contains a Privilege Context Switching Error (CWE-270) vulnerability in the handling of ambient capabilities th…EPSS 2.0%8.1CVE-2024-5154Kubernetes cri-o path traversal vulnerabilityA flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (“../“). This flaw…EPSS 1.2%7.8CVE-2022-4318Kubernetes cri-o improper control of dynamically-managed code vulnerabilityA vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment vari…EPSS 0.29%7.5CVE-2022-1708Kubernetes cri-o uncontrolled resource consumption vulnerabilityA vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the Kube API. The ExecSync reque…EPSS 3.1%5.3CVE-2022-3466Kubernetes cri-o incorrect default permissions vulnerabilityThe version of cri-o as released for Red Hat OpenShift Container Platform 4.9.48, 4.10.31, and 4.11.6 via RHBA-2022:6316, RHBA-2022:6257, and RHBA-20…EPSS 0.21%5.3CVE-2022-27652Kubernetes cri-o incorrect default permissions vulnerabilityA flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker En…EPSS 0.25%5.0CVE-2019-14891Kubernetes cri-o vulnerabilityA flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup. This can result in container management (…EPSS 0.80%

Source: NIST National Vulnerability Database (record CVE-2022-2995), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.