Critical Kubernetes Image Builder flaw gives SSH root access to VMs

Share:

A critical vulnerability in Kubernetes could allow unauthorized SSH access to a virtual machine running an image created with the Kubernetes Image Builder project.

Kubernetes is an open-source platform that helps automate the deployment, scale, and operate virtual containers – lightweight environments for applications to run.

With Kubernetes Image Builder, users can create virtual machine (VM) images for various Cluster API (CAPI) providers, like Proxmox or Nutanix, that run the Kubernetes environment. These VMs are then used to set up nodes (servers) that become part of a Kubernetes cluster.

A critical vulnerability in Kubernetes could allow unauthorized SSH access to a virtual machine running an image created with the Kubernetes Image Builder project.

Kubernetes is an open-source platform that helps automate the deployment, scale, and operate virtual containers – lightweight environments for applications to run.

With Kubernetes Image Builder, users can create virtual machine (VM) images for various Cluster API (CAPI) providers, like Proxmox or Nutanix, that run the Kubernetes environment. These VMs are then used to set up nodes (servers) that become part of a Kubernetes cluster.

If upgrading is not possible at this time, a temporary solution is to disable the builder account using the command:

usermod -L builder

More information about mitigation and how to check if your system is affected is available on this GitHub page.

The bulletin also warns that the same issue exists for images built with the Nutanix, OVA, QEMU or raw providers, but it has a medium-severity rating due to additional requirements for successful exploitation. The vulnerability is now identified as CVE-2024-9594.

Specifically, the flaw can only be exploited during the build process and requires an attacker to gain access to the image-creating VM and perform actions for the default credentials to persist, thus allowing future access to the VM.

The same fix and mitigation recommendation apply for CVE-2024-9594.

Bill Toulas

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
9:02 pm, Jan 31, 2025
weather icon 7°C
L: 6° | H: 7°
overcast clouds
Humidity: 92 %
Pressure: 1028 mb
Wind: 5 mph E
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 7:40 am
Sunset: 4:47 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 9:00 pm
weather icon
6° | 7°°C 0 mm 0% 8 mph 90 % 1030 mb 0 mm/h
Sun Feb 02 9:00 pm
weather icon
2° | 8°°C 0 mm 0% 6 mph 86 % 1026 mb 0 mm/h
Mon Feb 03 9:00 pm
weather icon
2° | 9°°C 0 mm 0% 5 mph 92 % 1027 mb 0 mm/h
Tue Feb 04 9:00 pm
weather icon
3° | 9°°C 0 mm 0% 9 mph 93 % 1028 mb 0 mm/h
Wed Feb 05 9:00 pm
weather icon
4° | 8°°C 0.51 mm 51% 7 mph 86 % 1045 mb 0 mm/h
Tomorrow 12:00 am
weather icon
5° | 6°°C 0 mm 0% 5 mph 90 % 1028 mb 0 mm/h
Tomorrow 3:00 am
weather icon
5° | 6°°C 0 mm 0% 6 mph 84 % 1029 mb 0 mm/h
Tomorrow 6:00 am
weather icon
5° | 5°°C 0 mm 0% 4 mph 80 % 1029 mb 0 mm/h
Tomorrow 9:00 am
weather icon
5° | 5°°C 0 mm 0% 3 mph 79 % 1030 mb 0 mm/h
Tomorrow 12:00 pm
weather icon
6° | 6°°C 0 mm 0% 8 mph 71 % 1029 mb 0 mm/h
Tomorrow 3:00 pm
weather icon
6° | 6°°C 0 mm 0% 6 mph 73 % 1027 mb 0 mm/h
Tomorrow 6:00 pm
weather icon
6° | 6°°C 0 mm 0% 6 mph 73 % 1027 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
4° | 4°°C 0 mm 0% 6 mph 82 % 1026 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€97,848.52
-3.28%
Ethereum(ETH)
€3,190.45
2.27%
XRP(XRP)
€2.90
-3.48%
Tether(USDT)
€0.96
-0.06%
Solana(SOL)
€220.87
-4.03%
USDC(USDC)
€0.96
0.00%
Dogecoin(DOGE)
€0.313779
-1.82%
Shiba Inu(SHIB)
€0.000018
0.23%
Pepe(PEPE)
€0.000013
8.08%
Scroll to Top