A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process. Virtual machine images built using the Proxmox provider do not disable these default credentials, and nodes using the resulting images may be accessible via these default credentials. The credentials can be used to gain root access. Kubernetes clusters are only affected if their nodes use VM images created via the Image Builder project with its Proxmox provider.
History

Thu, 17 Oct 2024 01:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1392
References
Metrics threat_severity

None

threat_severity

Critical


Wed, 16 Oct 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Kubernetes
Kubernetes image Builder
CPEs cpe:2.3:a:kubernetes:image_builder:*:*:*:*:*:*:*:*
Vendors & Products Kubernetes
Kubernetes image Builder
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Oct 2024 20:45:00 +0000

Type Values Removed Values Added
Description A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process. Virtual machine images built using the Proxmox provider do not disable these default credentials, and nodes using the resulting images may be accessible via these default credentials. The credentials can be used to gain root access. Kubernetes clusters are only affected if their nodes use VM images created via the Image Builder project with its Proxmox provider.
Title VM images built with Image Builder and Proxmox provider use default credentials
Weaknesses CWE-798
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: kubernetes

Published: 2024-10-15T20:33:43.138Z

Updated: 2024-10-16T18:56:40.632Z

Reserved: 2024-10-03T16:33:36.995Z

Link: CVE-2024-9486

cve-icon Vulnrichment

Updated: 2024-10-16T18:56:10.486Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-15T21:15:11.573

Modified: 2024-11-08T20:56:54.807

Link: CVE-2024-9486

cve-icon Redhat

Severity : Critical

Publid Date: 2024-10-16T18:03:32Z

Links: CVE-2024-9486 - Bugzilla