GHSA-phjr-8j92-w5v7 · Severity: high · Ecosystem: go — CRI-O incorrect handling of supplementary groups may lead to sensitive information disclosure
Incorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.
Conclusion & alert: CVE-2022-2995 is rated Exploit Available (53.4/100): CVSS High severity, with low exploitation likelihood (EPSS 0.36%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.03% | 0.36% | +0.33% |
| 2 | 2025-11-21 | 0.05% | 0.03% | -0.02% |
| 3 | 2025-11-18 | — | 0.05% | — |
Full EPSS history (7 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.1 | 3.1 | HIGH |
|
1.8 | 5.2 | [email protected] |
| 7.1 | 3.1 | HIGH |
|
1.8 | 5.2 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
GHSA-phjr-8j92-w5v7 · Severity: high · Ecosystem: go — CRI-O incorrect handling of supplementary groups may lead to sensitive information disclosure
| vendor | priority | summary | link |
|---|---|---|---|
redhat
|
low | — | https://access.redhat.com/security/cve/CVE-2022-2995 |
suse
|
medium | CVE-2022-2995 severity moderate: SUSE including 2 source package names (cri-o, cri-o-kubeadm-criconfig), 2 product×package rows across 1 product lines (SUSE CaaS Platform 4.0): Will Not Fix 2. | https://www.suse.com/security/cve/CVE-2022-2995/ |
ubuntu
|
medium | CVE-2022-2995 medium priority: Ubuntu including 1 source packages (cri-o), 4 status rows across 4 suites (focal, jammy, noble, upstream): DNE 3, needs-triage 1. | https://ubuntu.com/security/CVE-2022-2995 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| kubernetes | cri-o | 1.25.0 | cpe:2.3:a:kubernetes:cri-o:1.25.0:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/cri-o/cri-o/pull/6159 | Patch Third Party Advisory |
| https://www.benthamsgaze.org/2022/08/22/vulnerability-in-linux-containers-investigation-and-mitigation/ | Exploit Third Party Advisory |