wxvl/doc/2024-10/【漏洞预警】Kubernetes Image Builder凭证管理不当漏洞CVE-2024-9486.md

8 lines
1011 B
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# 【漏洞预警】Kubernetes Image Builder凭证管理不当漏洞CVE-2024-9486
cexlife 飓风网络安全 2024-10-17 21:06
![](https://mmbiz.qpic.cn/mmbiz_png/ibhQpAia4xu02gFk1NXySJyibl7HCOlKYCe81YFfyapITr3SThfVSxXVKVlOznLmzvUdGQR9EepZyiax5Eo55cpa1w/640?wx_fmt=png&from=appmsg "")
**漏洞描述:**Kubernetes官方发布安全公告,修复了Kubernetes Kubernetes Image Builder中存在的一处凭证管理不当漏洞,该漏洞是由于在镜像构建过程中启用了默认凭据,使用Proxmox提供程序构建的虚拟机镜像在构建过程中不会禁用这些默认凭据,攻击者可以通过这些凭证访问构建后的节点VM。**修复建议:正式防护方案:**针对此漏洞,官方已经发布了漏洞修复版本,请立即更新到安全版本:Kubernetes Image Builder >= v0.1.38**下载链接:**https://github.com/kubernetes-sigs/image-builder/releases/tag/v0.1.38在将 Kubernetes Image Builder 升级到安全版本后需要重新构建VM镜像并部署。