Critical Kubernetes Image Builder Flaws Could Lead VM Compromise
Amber | Vulnerability Report
Download PDFTwo vulnerabilities have been discovered in Kubernetes environments that use the Image Builder tool to create VM images for cluster setup. One of these, identified CVE-2024-9486, allows attackers to exploit default SSH credentials in Proxmox-based VM images, leading to root access and full system compromise. The other, CVE-2024-9594, requires access during the image build process and enables persistence of default credentials. To mitigate these risks, users should upgrade to Image Builder v0.1.38 or manually disable default builder accounts.
What’s new on HivePro
Get through updates and upcoming events, and more directly in your inbox