HIGH8.1
GHSA-27wf-5967-98gx
Kubernetes kubelet arbitrary command execution
Quick fix
GHSA-27wf-5967-98gx — k8s.io/kubernetes: upgrade to the fixed version with the command below.
go get k8s.io/kubernetes@v1.28.12Details
The Kubernetes kubelet component allows arbitrary command execution via specially crafted gitRepo volumes.This issue affects kubelet: through 1.28.11, from 1.29.0 through 1.29.6, from 1.30.0 through 1.30.2.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-10220[ADVISORY]
- https://github.com/kubernetes/kubernetes/issues/128885[WEB]
- https://github.com/kubernetes/kubernetes/commit/1ab06efe92d8e898ca1931471c9533ce94aba29b[WEB]
- https://github.com/kubernetes/kubernetes[PACKAGE]
- https://groups.google.com/g/kubernetes-security-announce/c/ptNgV5Necko[WEB]
- https://pkg.go.dev/vuln/GO-2024-3286[WEB]
- http://www.openwall.com/lists/oss-security/2024/11/20/1[WEB]