CVE-2024-9594 is a critical security flaw in Kubernetes Image Builder versions <= v0.1.37, affecting VM images built using Nutanix, OVA, QEMU, or raw providers. During the image build process, default credentials are enabled, allowing an attacker to gain root access to the VM. While these credentials are disabled post-build, an attacker could exploit this vulnerability if they accessed the VM during its creation to modify the image. The vulnerability carries a CVSS score of 8.1 (HIGH), indicating a high severity due to its network-based attack vector, low attack complexity, and potential for complete compromise (confidentiality, integrity, and availability). The FAUCET Risk Score is 65/100, and the CWE is CWE-798 (Use of Hard-coded Credentials). Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, with only one mention and one article, suggesting limited public awareness despite its critical nature.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.1.38CPE matchmatch criteria | cpe:2.3:a:kubernetes-sigs:image_builder:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
VM images built with Image Builder with some providers use default credentials during builds in github.com/kubernetes-sigs/image-builder
Oct 15, 2024kubernetes-image-builder: VM images built with Image Builder with some providers use default credentials during builds
Oct 15, 2024VM images built with Image Builder with some providers use default credentials during builds
VM images built with Image Builder with some providers use default credentials during builds
VM images built with Image Builder with some providers use default credentials during builds
VM images built with Image Builder with some providers use default credentials during builds