CVE-2024-9594
Last modified
CVE-2024-9594 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process when using the Nutanix, OVA, QEMU or raw providers. The credentials can be used to gain root access. EPSS estimates a 1.64% chance of exploitation in the next 30 days.
Description
A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process when using the Nutanix, OVA, QEMU or raw providers. The credentials can be used to gain root access. The credentials are disabled at the conclusion of the image build process. Kubernetes clusters are only affected if their nodes use VM images created via the Image Builder project. Because these images were vulnerable during the image build process, they are affected only if an attacker was able to reach the VM where the image build was happening and used the vulnerability to modify the image at the time the image build was occurring.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Kubernetes-Sigs | Image Builder | < 0.1.38 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-9594?
How severe is CVE-2024-9594?
How do I fix CVE-2024-9594?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-9588The Category and Taxonomy Meta Fields plugin for WordPress i…5.4
- CVE-2024-9589The Category and Taxonomy Meta Fields plugin for WordPress i…4.8
- CVE-2024-9590The Category and Taxonomy Meta Fields plugin for WordPress i…4.8
- CVE-2024-9591The Category and Taxonomy Image plugin for WordPress is vuln…4.8
- CVE-2024-9592The Easy PayPal Gift Certificate plugin for WordPress is vul…6.1
- CVE-2024-9593The Time Clock plugin and Time Clock Pro plugin for WordPres…8.3
- CVE-2024-9595The TablePress – Tables in WordPress made easy plugin for Wo…5.4
- CVE-2024-9596An issue has been discovered in GitLab EE affecting all vers…5.3
- CVE-2024-9597A Path Traversal vulnerability exists in the `/wipe_database…7.1
- CVE-2024-9598The AMP for WP – Accelerated Mobile Pages plugin for WordPre…8.8
- CVE-2024-9599The Popup Box WordPress plugin before 4.7.8 does not saniti…5.4
- CVE-2024-9600The Ditty WordPress plugin before 3.1.47 does not sanitise …4.8
Are you affected by CVE-2024-9594?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
