PT-2024-6906 · Unknown+1 · Kubernetes Image Builder+1

Nicolai Rybnikar

+1

·

Published

2024-10-14

·

Updated

2025-10-07

·

CVE-2024-9486

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Kubernetes Image Builder versions <= v0.1.37
Description A security issue was discovered in the Kubernetes Image Builder where default credentials are enabled during the image build process. Virtual machine images built using the Proxmox provider do not disable these default credentials, and nodes using the resulting images may be accessible via these default credentials. The credentials can be used to gain root access. Kubernetes clusters are only affected if their nodes use VM images created via the Image Builder project with its Proxmox provider. This issue allows attackers to exploit default credentials to take over virtual machines using certain image builds.
Recommendations For Kubernetes Image Builder versions <= v0.1.37, update to v0.1.38 to mitigate this issue. As a temporary workaround, consider disabling the default credentials in the image build process to prevent unauthorized access. Restrict access to the vulnerable VM images to minimize the risk of exploitation. Avoid using the default credentials in the affected API endpoints until the issue is resolved.

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

BDU:2024-08129
CVE-2024-9486
GHSA-9224-GGVW-WH7V
GO-2024-3203
OPENSUSE-SU-2024:0350-1
OPENSUSE-SU-2024:14447-1
OPENSUSE-SU-2024_3911-1
SUSE-SU-2024:3911-1

Affected Products

Kubernetes Image Builder
Suse