Threat Advisories:

Critical Kubernetes Image Builder Flaws Could Lead VM Compromise

Amber | Vulnerability Report
Download PDF
Two vulnerabilities have been discovered in Kubernetes environments that use the Image Builder tool to create VM images for cluster setup. One of these, identified CVE-2024-9486, allows attackers to exploit default SSH credentials in Proxmox-based VM images, leading to root access and full system compromise. The other, CVE-2024-9594, requires access during the image build process and enables persistence of default credentials. To mitigate these risks, users should upgrade to Image Builder v0.1.38 or manually disable default builder accounts.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox

Cyber Horizons 2025

What Last Year’s Attacks Reveal About Today’s Risks

Watch the Webinar on-demand and get a FREE copy of our Cyber Horizons 2025 report.

Our Speakers
Speaker 1

Prateek Bhajanka Global Field CISO & Former Gartner Analyst Hive Pro Inc.

Speaker 2

Ankit Mani Manager Threat Intel HiveForce Labs

Speaker 3

Sreevani Tonipe Senior Threat Researcher HiveForce Labs