Critical Kubernetes Image Builder Flaws Could Lead VM Compromise

Amber | Vulnerability Report
Download PDF
Two vulnerabilities have been discovered in Kubernetes environments that use the Image Builder tool to create VM images for cluster setup. One of these, identified CVE-2024-9486, allows attackers to exploit default SSH credentials in Proxmox-based VM images, leading to root access and full system compromise. The other, CVE-2024-9594, requires access during the image build process and enables persistence of default credentials. To mitigate these risks, users should upgrade to Image Builder v0.1.38 or manually disable default builder accounts.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox