Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

[GHSA-9224-ggvw-wh7v] VM images built with Image Builder and Proxmox provider use default credentials in github.com/kubernetes-sigs/image-builder#5000

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.

Already on GitHub?Sign in to your account

Conversation

akaday
Copy link

Updates

  • CVSS v3

Comments
VM images built with Image Builder and Proxmox provider use default credentials in github.com/kubernetes-sigs/image-builder

Description: A critical security vulnerability has been identified in Kubernetes Image Builder versions ≤ v0.1.37, where default credentials remain enabled during the image build process. Virtual machine images created using the Proxmox provider are particularly affected, as these default credentials are not disabled. Consequently, nodes utilizing these images may be accessible via these default credentials, potentially allowing unauthorized root access. Only Kubernetes clusters with nodes that employ VM images generated via the Image Builder project with the Proxmox provider are impacted.

References:

NVD

Kubernetes Issue #128006

Image Builder Pull Request#1595

Google Groups Announcement

Source Code Location: Image Builder Repository

Affected products: Ecosystem: Go Package name: github.com/kubernetes-sigs/image-builder Affected versions: < 0.1.38 Patched versions: 0.1.38

Severity: Critical (9.3)

CVSS Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Weaknesses:

CWE-798: Use of Hard-coded Credentials

Reason for change: Provide supporting evidence for this change, such as reference links, code commits, or broader context.

@github-actionsgithub-actionsbot changed the base branch frommain toakaday/advisory-improvement-5000November 11, 2024 05:46
@shelbycshelbyc added the invalidThis doesn't seem right labelNov 12, 2024
@github-actionsgithub-actionsbot deleted the akaday-GHSA-9224-ggvw-wh7v branchNovember 12, 2024 16:01
Sign up for freeto join this conversation on GitHub. Already have an account?Sign in to comment
Reviewers
No reviews
Assignees
No one assigned
Labels
invalidThis doesn't seem right
Projects
None yet
Milestone
No milestone
Development

Successfully merging this pull request may close these issues.

2 participants
@akaday@shelbyc

[8]ページ先頭

©2009-2025 Movatter.jp