Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-10220

Опубликовано: 08 нояб. 2024
Источник: redhat
CVSS3: 8.1
EPSS Средний

Описание

The Kubernetes kubelet component allows arbitrary command execution via specially crafted gitRepo volumes.This issue affects kubelet: through 1.28.11, from 1.29.0 through 1.29.6, from 1.30.0 through 1.30.2.

A flaw was found in the Kubelet component from the Kubernetes package. This flaw allows an attacker to create a pod and an associated gitRepo volume to execute arbitrary commands outside the container, bypassing the intended isolation between the container and the host.

Отчет

This vulnerability is classified as important severity due to its potential to allow arbitrary command execution beyond the container boundary, which can lead to severe security breaches. By leveraging the hooks folder in the target repository associated with the gitRepo volume, an attacker can execute commands on the host system or other pods within the cluster. This can result in unauthorized access, data exfiltration, or privilege escalation, making it far more impactful than a moderate vulnerability.

Меры по смягчению последствий

Users can restrict the usage of gitRepo volumes in their cluster using policies such as ValidatingAdmissionPolicy. The following CEL expression can be used as part of the policy to restrict the use of gitRepo volumes:

has(object.spec.volumes) || !object.spec.volumes.exists(v, has(v.gitRepo)) ~~

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 1.2ansible-towerWill not fix
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/ee-supported-rhel8Affected
Red Hat Ansible Automation Platform 2automation-controllerWill not fix
Red Hat Discoverydiscovery-server-containerNot affected
Red Hat Enterprise Linux 9fence-agentsWill not fix
Red Hat OpenShift Container Platform 4openshift4/cnf-tests-rhel8Not affected
Red Hat OpenShift Container Platform 4openshift4/ose-ansible-operatorNot affected
Red Hat OpenShift Container Platform 4openshift4/ztp-site-generate-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-653
https://bugzilla.redhat.com/show_bug.cgi?id=2323060kubernetes: Arbitrary command execution through gitRepo volume

EPSS

Процентиль: 93%
0.11286
Средний

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
7 месяцев назад

The Kubernetes kubelet component allows arbitrary command execution via specially crafted gitRepo volumes.This issue affects kubelet: through 1.28.11, from 1.29.0 through 1.29.6, from 1.30.0 through 1.30.2.

CVSS3: 8.1
nvd
7 месяцев назад

The Kubernetes kubelet component allows arbitrary command execution via specially crafted gitRepo volumes.This issue affects kubelet: through 1.28.11, from 1.29.0 through 1.29.6, from 1.30.0 through 1.30.2.

CVSS3: 8.1
msrc
5 месяцев назад

Описание отсутствует

CVSS3: 8.1
debian
7 месяцев назад

The Kubernetes kubelet component allows arbitrary command execution vi ...

CVSS3: 8.1
github
7 месяцев назад

Kubernetes kubelet arbitrary command execution

EPSS

Процентиль: 93%
0.11286
Средний

8.1 High

CVSS3