CyberzSOC

Publication detail
← Back to advisories & guidance

2024-112: Critical Vulnerability in Kubernetes ↗ source

October 17, 2024 CERT-EU Advisory

Summary

It is recommended updating the Kubernetes Image Builder, and redeploying or mitigating Virtual Machines (VMs) created by the vulnerable Kubernetes Image Builder. The flaw affects Kubernetes Image Builder version 0.1.37 and earlier. It enables root access via SSH using default credentials on VMs built with the vulnerable version of Kubernetes Image For images built with the Proxmox provider, the vulnerability has been assigned CVE-2024-9486 , For images built with the Nutanix, OVA, QEMU or raw providers, the vulnerability has been assigned CVE-2024-9594 , with a CVSS of 6.3. It is strongly recommended updating the Kubernetes Image Builder and redeploying VMs created by the vulnerable Kubernetes Image Builder. It is possible to mitigate the vulnerability in affected VMs by disabling the builder account: The Linux command last builder can be used to view logins to the affected builder account.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-9486 9.8 Critical Kubernetes Image Builder A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build proc…
CVE-2024-9594 6.3 Medium Kubernetes Image Builder A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build proc…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

No KEV-catalogued vendors are named in this publication.