Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-9594

Опубликовано: 15 окт. 2024
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 6.3

Описание

A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process when using the Nutanix, OVA, QEMU or raw providers. The credentials can be used to gain root access. The credentials are disabled at the conclusion of the image build process. Kubernetes clusters are only affected if their nodes use VM images created via the Image Builder project. Because these images were vulnerable during the image build process, they are affected only if an attacker was able to reach the VM where the image build was happening and used the vulnerability to modify the image at the time the image build was occurring.

РелизСтатусПримечание
devel

DNE

esm-apps/focal

not-affected

code not present
esm-apps/jammy

not-affected

code not present
esm-apps/noble

not-affected

code not present
focal

ignored

end of standard support, was needs-triage
jammy

not-affected

code not present
noble

not-affected

code not present
oracular

ignored

end of life, was needs-triage
plucky

DNE

upstream

needs-triage

Показывать по

EPSS

Процентиль: 85%
0.02527
Низкий

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.3
redhat
больше 1 года назад

A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process when using the Nutanix, OVA, QEMU or raw providers. The credentials can be used to gain root access. The credentials are disabled at the conclusion of the image build process. Kubernetes clusters are only affected if their nodes use VM images created via the Image Builder project. Because these images were vulnerable during the image build process, they are affected only if an attacker was able to reach the VM where the image build was happening and used the vulnerability to modify the image at the time the image build was occurring.

CVSS3: 6.3
nvd
больше 1 года назад

A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process when using the Nutanix, OVA, QEMU or raw providers. The credentials can be used to gain root access. The credentials are disabled at the conclusion of the image build process. Kubernetes clusters are only affected if their nodes use VM images created via the Image Builder project. Because these images were vulnerable during the image build process, they are affected only if an attacker was able to reach the VM where the image build was happening and used the vulnerability to modify the image at the time the image build was occurring.

CVSS3: 6.3
github
больше 1 года назад

VM images built with Image Builder with some providers use default credentials during builds in github.com/kubernetes-sigs/image-builder

CVSS3: 6.3
fstec
больше 1 года назад

Уязвимость программного средства для создания образов контейнеров Kubernetes Image Builder, связанная с использованием жестко закодированных учетных данных, позволяющая нарушителю получить доступ к виртуальной машине

suse-cvrf
больше 1 года назад

Security update for govulncheck-vulndb

EPSS

Процентиль: 85%
0.02527
Низкий

6.3 Medium

CVSS3