GHSA-9224-ggvw-wh7v

Suggest an improvement
Source
https://github.com/advisories/GHSA-9224-ggvw-wh7v
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/10/GHSA-9224-ggvw-wh7v/GHSA-9224-ggvw-wh7v.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-9224-ggvw-wh7v
Aliases
Published
2024-10-15T21:30:39Z
Modified
2024-11-08T22:16:35Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
VM images built with Image Builder and Proxmox provider use default credentials in github.com/kubernetes-sigs/image-builder
Details

A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process. Virtual machine images built using the Proxmox provider do not disable these default credentials, and nodes using the resulting images may be accessible via these default credentials. The credentials can be used to gain root access. Kubernetes clusters are only affected if their nodes use VM images created via the Image Builder project with its Proxmox provider.

Database specific
{
    "nvd_published_at": "2024-10-15T21:15:11Z",
    "cwe_ids": [
        "CWE-798"
    ],
    "severity": "CRITICAL",
    "github_reviewed": true,
    "github_reviewed_at": "2024-10-17T20:28:15Z"
}
References

Affected packages

Go / github.com/kubernetes-sigs/image-builder

Package

Name
github.com/kubernetes-sigs/image-builder
View open source insights on deps.dev
Purl
pkg:golang/github.com/kubernetes-sigs/image-builder

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.1.38