Tech News
Hard-Coded Credentials Vulnerability In Kubernetes Image Builder
A critical vulnerability has been addressed with the latest release of Kubernetes Image Builder. This vulnerability was related to hard-coded credentials that could potentially allow unauthorized access to malicious actors.
Kubernetes Image Builder Vulnerability
According to the latest advisory, two security issues have been patched in the latest Kubernetes Image Builder release.
One of these issues, identified as CVE-2024-9486, was caused by hard-coded credentials that were active during the image-building process. These credentials could be exploited to gain root access to nodes using the images, particularly when built with the Proxmox provider.
This vulnerability affected Kubernetes Image Builder versions v0.1.37 and earlier when built with the Proxmox provider. More details about this vulnerability can be found on GitHub.
To address the vulnerability, Kubernetes recommends rebuilding images using the patched Image Builder versions and deploying them to the virtual machines.
This critical vulnerability received a CVSS score of 9.8 and was initially discovered by security researcher Nicolai Rybnikar from Rybnikar Enterprises GmbH. The issue was promptly addressed by the project team, and a fix was released with Kubernetes Image Builder v0.1.38. Marcus Noble from the Image Builder project was acknowledged for patching the issue.
Furthermore, the same Image Builder release also fixed another security flaw, identified as CVE-2024-9594. This medium-severity vulnerability (CVSS 6.3) is similar to the previous issue but affects images built with Nutanix, OVA, QEMU, or raw providers. Details about this vulnerability can be found on GitHub.
Users are advised to update to Kubernetes Image Builder version 0.1.38 or later to ensure they receive all the necessary patches and avoid potential risks. If an immediate update is not possible, users can disable the builder account on affected virtual machines using the command: usermod -L builder
.
Share your thoughts in the comments section below.
-
Motivation5 months ago
The Top 20 Motivational Instagram Accounts to Follow (2024)
-
Tech News5 months ago
Bangladeshi police agents accused of selling citizens’ personal information on Telegram
-
Destination1 month ago
Singapore Airlines CEO set to join board of Air India, BA News, BA
-
Self Development5 months ago
Don’t Waste Your Time in Anger, Regrets, Worries and Grudges
-
Tech News3 months ago
Mastering data privacy in the age of AI
-
Guides & Tips4 months ago
Satisfy Your Meat and BBQ Cravings While in Texas
-
Toys5 months ago
15 of the Best Trike & Tricycles Mums Recommend
-
Tech News3 months ago
Soccer team’s drone at center of Paris Olympics spying scandal