VM images built with Image Builder and Proxmox provider use default credentials
Published Oct 15, 2024
9.3
CRITICALCVSS 4.0
EPSS 2.21%
Description
A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process. Virtual machine images built using the Proxmox provider do not disable these default credentials, and nodes using the resulting images may be accessible via these default credentials. The credentials can be used to gain root access. Kubernetes clusters are only affected if their nodes use VM images created via the Image Builder project with its Proxmox provider.
Affected products
-
- Version 0StatusaffectedConstraints<=0.1.37
- Version 0.1.38StatusunaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Kubernetes | Image Builder | unaffected |
|
- < 0.1.38
-
- Version 0StatusaffectedConstraints<0.1.38
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Kubernetes | Image Builder | n/a |
|
No Red Hat product state for this CVE.
github.com/kubernetes-sigs/image-builder
Go
Introduced 0 Fixed 0.1.38
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/kubernetes-sigs/image-builder | 0 | 0.1.38 |
Remediation
Vendor solution
Rebuild any affected images using a fixed version of Image Builder. Re-deploy the fixed images to any affected VMs.
Red Hat statement
Red Hat has evaluated this vulnerability and its related components. No products are affected as the impacted component is not shipped in the Red Hat Product Portfolio.
References (8)
- https://access.redhat.com/security/cve/CVE-2024-9486 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2318845 Issue Tracking
- https://github.com/advisories/GHSA-9224-ggvw-wh7v Advisory
- https://github.com/kubernetes-sigs/image-builder/pull/1595 patch
- https://github.com/kubernetes/kubernetes/issues/128006 vendor-advisoryissue-trackingIssue Tracking
- https://groups.google.com/g/kubernetes-security-announce/c/UKJG-oZogfA/m/Lu1hcnHmAQAJ mailing-listVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-9486
- https://www.cve.org/CVERecord?id=CVE-2024-9486
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2024-9486 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2318845 | Issue Tracking | |
| https://github.com/advisories/GHSA-9224-ggvw-wh7v | Advisory | |
| https://github.com/kubernetes-sigs/image-builder/pull/1595 | patch | |
| https://github.com/kubernetes/kubernetes/issues/128006 | vendor-advisoryissue-trackingIssue Tracking | |
| https://groups.google.com/g/kubernetes-security-announce/c/UKJG-oZogfA/m/Lu1hcnHmAQAJ | mailing-listVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2024-9486 | ||
| https://www.cve.org/CVERecord?id=CVE-2024-9486 |
Change history (0)
No recorded changes yet.