Kubernetes Image Builder Vulnerabilities
ID: 606477f2-f138-5dcc-9277-425402508158
STIX ID: report--606477f2-f138-5dcc-9277-425402508158
Feed Name: Kudelski Security
Two vulnerabilities in Kubernetes Image Builder (CVE-2024-9486, CVSS 9.8; CVE-2024-9594, CVSS 6.3) affect Image Builder versions up to v0.1.37 when using certain providers (notably Proxmox, and also Nutanix, OVA, QEMU, raw). CVE-2024-9486 can leave default builder credentials enabled after image build allowing post-deployment root access, while CVE-2024-9594 is exploitable during the deployment cycle. The issues are resolved in v0.1.38 (randomized build-only passwords and disabling the builder account); recommended actions are to upgrade, rebuild and redeploy affected images and disable builder accounts where possible. Kudelski/CFC report no observed active exploitation and will continue monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
