A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process. Virtual machine images built using the Proxmox provider do not disable these default credentials, and nodes using the resulting images may be accessible via these default credentials. The credentials can be used to gain root access. Kubernetes clusters are only affected if their nodes use VM images created via the Image Builder project with its Proxmox provider.
References
Link | Resource |
---|---|
https://github.com/kubernetes-sigs/image-builder/pull/1595 | Patch |
https://github.com/kubernetes/kubernetes/issues/128006 | Issue Tracking |
https://groups.google.com/g/kubernetes-security-announce/c/UKJG-oZogfA/m/Lu1hcnHmAQAJ | Vendor Advisory |
Configurations
History
08 Nov 2024, 20:56
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/kubernetes-sigs/image-builder/pull/1595 - Patch | |
References | () https://github.com/kubernetes/kubernetes/issues/128006 - Issue Tracking | |
References | () https://groups.google.com/g/kubernetes-security-announce/c/UKJG-oZogfA/m/Lu1hcnHmAQAJ - Vendor Advisory | |
CPE | cpe:2.3:a:kubernetes:image_builder:*:*:*:*:*:*:*:* | |
First Time |
Kubernetes
Kubernetes image Builder |
16 Oct 2024, 16:38
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
15 Oct 2024, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-10-15 21:15
Updated : 2024-11-08 20:56
NVD link : CVE-2024-9486
Mitre link : CVE-2024-9486
CVE.ORG link : CVE-2024-9486
JSON object : View
Products Affected
kubernetes
- image_builder
CWE
CWE-798
Use of Hard-coded Credentials