Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS05MjI0LWdndnctd2g3ds4ABATP
VM images built with Image Builder and Proxmox provider use default credentials in github.com/kubernetes-sigs/image-builder
A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process. Virtual machine images built using the Proxmox provider do not disable these default credentials, and nodes using the resulting images may be accessible via these default credentials. The credentials can be used to gain root access. Kubernetes clusters are only affected if their nodes use VM images created via the Image Builder project with its Proxmox provider.
Permalink: https://github.com/advisories/GHSA-9224-ggvw-wh7vJSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS05MjI0LWdndnctd2g3ds4ABATP
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Critical
Classification: General
Published: about 1 month ago
Updated: 12 days ago
CVSS Score: 9.8
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Identifiers: GHSA-9224-ggvw-wh7v, CVE-2024-9486
References:
- https://nvd.nist.gov/vuln/detail/CVE-2024-9486
- https://github.com/kubernetes/kubernetes/issues/128006
- https://github.com/kubernetes-sigs/image-builder/pull/1595
- https://groups.google.com/g/kubernetes-security-announce/c/UKJG-oZogfA/m/Lu1hcnHmAQAJ
- https://github.com/advisories/GHSA-9224-ggvw-wh7v
Blast Radius: 1.0
Affected Packages
go:github.com/kubernetes-sigs/image-builder
Dependent packages: 0Dependent repositories: 0
Downloads:
Affected Version Ranges: < 0.1.38
Fixed in: 0.1.38
All affected versions: 0.1.0, 0.1.1, 0.1.2, 0.1.3, 0.1.4, 0.1.5, 0.1.6, 0.1.7, 0.1.8, 0.1.9, 0.1.10, 0.1.11, 0.1.12, 0.1.13, 0.1.14, 0.1.15, 0.1.16, 0.1.17, 0.1.18, 0.1.19, 0.1.20, 0.1.21, 0.1.22, 0.1.23, 0.1.24, 0.1.25, 0.1.26, 0.1.27, 0.1.28, 0.1.29, 0.1.30, 0.1.31, 0.1.32, 0.1.33, 0.1.34, 0.1.35, 0.1.36, 0.1.37
All unaffected versions: 0.1.38, 0.1.39