HomeSecurityCritical Kubernetes Image Builder vulnerability allows SSH access to VMs

Critical Kubernetes Image Builder vulnerability allows SSH access to VMs

A critical vulnerability in Kubernetes could allow unauthorized SSH access to a virtual machine running an image created with Kubernetes Image Builder.

See also: Vulnerability in Microsoft Dataverse allows privilege escalation

Kubernetes Image Builder vulnerability

Kubernetes is an open source platform that helps automate the deployment, scale, and operation of virtual containers – lightweight environments for running applications.

With Kubernetes Image Builder, users can create virtual machine (VM) images for various Cluster API (CAPI) providers, such as Proxmox or Nutanix, that run the Kubernetes environment. These VMs are then used to create nodes (servers) that become part of a Kubernetes cluster.

According to a security advisory on the Kubernetes community forums, the critical vulnerability affects VM images created with the Proxmox provider in Image Builder version 0.1.37 or earlier

The issue is currently tracked as CVE-2024-9486 and consists of using default credentials that were enabled during the image creation process and not disabled afterwards. A threat actor aware of this could connect via an SSH connection and use these credentials to gain root access to vulnerable VMs

The workaround for the vulnerability is to rebuild the affected VM images using Kubernetes Image Builder version 0.1.38 or later, which sets a randomly generated password during the build process and also disables the default “builder” account after the process is complete.

See also: CISA: Adds SolarWinds WHD vulnerability to KEV List

Critical Kubernetes Image Builder vulnerability allows SSH access to VMs

If upgrading is not possible at this time, a temporary solution is to disable the builder account using the command:

usermod -L builder

More information about vulnerability mitigation and how to check if your Kubernetes Image Builder system is affected is available on this GitHub page.

The bulletin also warns that the same issue exists for images built with Nutanix, OVA, QEMU , or raw product, but has a medium severity due to additional requirements for successful exploitation. The vulnerability is now identified as CVE-2024-9594.

Specifically, the flaw can only be exploited during the build process and requires an attacker to gain access to the VM that is creating the image and perform actions to preserve the default credentials, thereby allowing future access to the VM.

The same patch and mitigation recommendation applies to CVE-2024-9594.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Vulnerabilities in Splunk Enterprise allow hackers to execute remote code

In the field of IT security, critical vulnerabilities, such as the one found in Kubernetes Image Builder, refer to a serious flaw or weakness in a system that can be exploited by attackers to gain unauthorized access or cause damage. These vulnerabilities can include software flaws, weaknesses in system design, or deficiencies in the implementation of security protocols. Detecting and remediating these vulnerabilities is critical to ensuring the integrity, confidentiality, and availability of information resources in an organization.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS