CVE-2024-9486

Description

A vulnerability was found in Kubernetes Image Builder. Kubernetes Image Builder default credentials are enabled during the image build process when using Proxmox. The credentials can be used to gain root access. The credentials are disabled after the image build process. Kubernetes clusters are only affected if their nodes use VM images created via the Image Builder project.

Statement

Red Hat has evaluated this vulnerability and its related components. No products are affected as the impacted component is not shipped in the Red Hat Product Portfolio.

Understanding the Weakness (CWE)

Authentication

Technical Impact: Gain Privileges or Assume Identity

Frequently Asked Questions

Want to get errata notifications? Sign up here.