Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <3E7469E3-7A05-4823-843A-FEE4B752EBE9@amazon.com>
Date: Wed, 15 Jan 2025 22:11:57 +0000
From: "Vellore Rajakumar, Sri Saran Balaji" <srajakum@...zon.com>
To: "oss-security@...ts.openwall.com" <oss-security@...ts.openwall.com>
Subject: [kubernetes] CVE-2024-9042: Command Injection affecting Windows nodes
 via nodes/*/logs/query API

Hello Kubernetes Community,
A security vulnerability has been discovered in Kubernetes windows nodes that could allow a user with the ability to query a node's '/logs' endpoint to execute arbitrary commands on the host.

This issue has been rated Medium with a CVSS v3.1 score of 5.9 (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N<https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N>) and assigned CVE-2024-9042.

Am I vulnerable?
This CVE affects only Windows worker nodes. Your worker node is vulnerable to this issue if it is running one of the affected versions listed below.

Affected Components

  *   Kubelet

Affected Versions

  *   v1.32.0
  *   v1.31.0 to v1.31.4
  *   v1.30.0 to v1.30.8
  *   <=v1.29.12

How do I mitigate this vulnerability?
To mitigate this vulnerability, you need to upgrade the Kubelet on your Windows worker nodes to one of the fixed versions listed below.

Fixed Versions

  *   v1.32.1
  *   v1.31.5
  *   v1.30.9
  *   v1.29.13

Detection
To detect whether this vulnerability has been exploited, you can examine your cluster's audit logs to search for node 'logs' queries with suspicious inputs.

If you find evidence that this vulnerability has been exploited, please contact security@...ernetes.io<mailto:security@...ernetes.io>

Acknowledgements
This vulnerability was reported by Peled, Tomer and mitigated by Aravindh Puthiyaprambil.

Thank You,
Balaji on behalf of the Kubernetes Security Response Committee

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.