Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[GHSA-9224-ggvw-wh7v] VM images built with Image Builder and Proxmox provider use default credentials in github.com/kubernetes-sigs/image-builder #5000

Closed

Conversation

akaday
Copy link

@akaday akaday commented Nov 11, 2024

Updates

  • CVSS v3

Comments
VM images built with Image Builder and Proxmox provider use default credentials in github.com/kubernetes-sigs/image-builder

Description: A critical security vulnerability has been identified in Kubernetes Image Builder versions ≤ v0.1.37, where default credentials remain enabled during the image build process. Virtual machine images created using the Proxmox provider are particularly affected, as these default credentials are not disabled. Consequently, nodes utilizing these images may be accessible via these default credentials, potentially allowing unauthorized root access. Only Kubernetes clusters with nodes that employ VM images generated via the Image Builder project with the Proxmox provider are impacted.

References:

NVD

Kubernetes Issue #128006

Image Builder Pull Request #1595

Google Groups Announcement

Source Code Location: Image Builder Repository

Affected products: Ecosystem: Go Package name: github.com/kubernetes-sigs/image-builder Affected versions: < 0.1.38 Patched versions: 0.1.38

Severity: Critical (9.3)

CVSS Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Weaknesses:

CWE-798: Use of Hard-coded Credentials

Reason for change: Provide supporting evidence for this change, such as reference links, code commits, or broader context.

@github-actions github-actions bot changed the base branch from main to akaday/advisory-improvement-5000 November 11, 2024 05:46
@shelbyc shelbyc added the invalid This doesn't seem right label Nov 12, 2024
@github-actions github-actions bot deleted the akaday-GHSA-9224-ggvw-wh7v branch November 12, 2024 16:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
invalid This doesn't seem right
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants