Kubernetes Sigs maintains the image-builder project, a specialized tool for constructing and managing container images within Kubernetes environments, representing a narrow but strategically positioned component in the container orchestration supply chain. The disclosed vulnerabilities reflect the build-tooling and image-management context of this focused product. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kubernetes Sigs over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-9486CRITICAL A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process. Virtual machine images bui | Oct 15, 2024 | 9.8 | 31 | NO | NO |
CVE-2024-9594HIGH A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process when using the Nutanix, OVA | Oct 15, 2024 | 8.1 | 26 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kubernetes Sigs.
Media articles that mention a CVE ID that affects a product developed by Kubernetes Sigs — matched by CVE ID, not by vendor name.