PT-2024-6934 · Kubernetes+1 · Kubernetes Image Builder+1

Nicolai Rybnikar

+1

·

Published

2024-10-14

·

Updated

2024-11-08

·

CVE-2024-9594

CVSS v2.0

6.5

Medium

VectorAV:A/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Kubernetes Image Builder versions <= v0.1.37
Description A security issue was discovered in the Kubernetes Image Builder where default credentials are enabled during the image build process when using certain providers, such as Nutanix, OVA, QEMU, or raw. This allows an attacker to gain root access to the virtual machine. The credentials are disabled at the conclusion of the image build process. Kubernetes clusters are only affected if their nodes use VM images created via the Image Builder project and an attacker was able to reach the VM where the image build was happening and used the vulnerability to modify the image at the time the image build was occurring.
Recommendations For Kubernetes Image Builder versions <= v0.1.37, consider disabling the default credentials during the image build process as a temporary workaround until a patch is available. Restrict access to the VM where the image build is happening to minimize the risk of exploitation. Avoid using the vulnerable providers, such as Nutanix, OVA, QEMU, or raw, until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

BDU:2024-08157
CVE-2024-9594
GHSA-8JPG-62JC-HWHR
GO-2024-3204
OPENSUSE-SU-2024:0350-1
OPENSUSE-SU-2024:14447-1
OPENSUSE-SU-2024_3911-1
SUSE-SU-2024:3911-1

Affected Products

Kubernetes Image Builder
Suse