PT-2025-1258 · Unknown+2 · Kubernetes+1
Aravindh Puthiyaprambil
+3
·
Published
2025-01-15
·
Updated
2025-12-11
·
CVE-2024-9042
CVSS v2.0
6.6
Medium
| Vector | AV:N/AC:H/Au:S/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Kubernetes versions prior to 1.29.14
Kubernetes versions prior to 1.30.10
Kubernetes versions prior to 1.31.6
Description
This issue is a command injection affecting Windows worker nodes via the
/logs query API. The vulnerability allows attackers to execute arbitrary commands on the host machine. The pattern parameter of the NodeLogQuery feature is directly passed to PowerShell without filtering, enabling command injection for any user or service account with GET permissions on nodes/logs. Successful exploitation allows execution of commands with SYSTEM privileges on all Windows nodes.Recommendations
Upgrade Kubernetes to version 1.29.14 or later.
Upgrade Kubernetes to version 1.30.10 or later.
Upgrade Kubernetes to version 1.31.6 or later.
Fix
RCE
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Kubernetes