Critical Kubernetes Image Builder credential vulnerability allows for virtual machine SSH access | usagoldmines.com

There is a critical vulnerability in the Kubernetes Image Builder that allows threat actors to access different Virtual Machine (VM) images with ease. A patch is already available, so if you’re using the image building tool, make sure to update it to the latest version as soon as possible.

Kubernetes Image Builder is a tool that helps build and maintain container images for Kubernetes environments. It simplifies the building, packaging, and deployment of containerized applications by generating optimized and reproducible images ready for Kubernetes clusters.

However, when one builds a Kubernetes VM image, it comes with a set of default credentials, which are the same for every user. As a result, crooks can easily access virtual machines with root privileges.

Randomly generated password

According to The Register, VM images built with the Proxmox provider are most at risk. The flaw on this platform is tracked as CVE-2024-9486, and carries a severity rating of 9.8/10, meaning it’s critical. Image Builder version 0.1.37, or earlier, are flawed, and it is recommended users migrate to Image Builder v0.1.38, or later, as soon as possible.

In this version, every new image build will be given a randomly generated password, with the builder account being terminated at the end of the build process.

Users that end up upgrading Image Builder should also re-deploy new images to any affected VMs, the publication stressed.

Besides Proxmox, there are other providers who are at risk, too – including Nutanix, OVA, QEMU, and others: However, in these instances, the severity rating is 6.3, since they disable the default credentials at the end of the image build process, and thus give the threat actor a much smaller window of opportunity.

Those that are unable to apply the patch at the moment should disable the builder account and thus mitigate the risk.

Via The Register

More from TechRadar Pro

AWS has patched a rather embarrassing Kubernetes bugHere’s a list of the best firewalls todayThese are the best endpoint protection tools right now
​ 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

Asus ROG Thor III is a massive 1600W PSU that will handle the Nvidia RTX 5090 with ease - but could ...
X’s controversial changes to blocking and AI training sees half a million users leave for rival Blue...
Now on DVD: Windows 11 24H2 (yes, really) has been slimmed down and ready for action by Tiny11 devel...
Hulu is stealing the saddest rom-com I've seen with 91% on Rotten Tomatoes from Netflix – here’s whe...
Microsoft says it has lost 'weeks' worth of security logs for some products | usagoldmines.com
Emerging AI regulation will shape the future of data collection for business | usagoldmines.com
The AI at scale revolution disrupting industries | usagoldmines.com
Adobe shows off 3D rotation tool for flat drawings Kyle Orland | usagoldmines.com
Manufacturers release patch for SSD-related Windows 11 24H2 crashes | usagoldmines.com
How to auto-lock your PC when you step away (and why you should) | usagoldmines.com
Wireless 6G sets an incredible speed record, makes 5G feel like dial-up | usagoldmines.com
This cheap Bluetooth turntable looks ideal for vinyl beginners – with one potential problem | usago...
Max drops Dune: Prophecy's official trailer and proves that HBO is still the king of original TV sho...
Google Chrome on Android is about to get a massive upgrade for password managers that’s been a long ...
Sonos confirms some missing details about Arc Ultra – and says its app now has 90% of its missing fe...
This fast, budget-friendly 1TB portable SSD just got even cheaper | usagoldmines.com
iPad Mini 7 Benchmarks Confirm 8GB RAM, 5-Core GPU's Slower Speeds Hartley Charlton | usagoldmines.c...
Where to buy the Fujifilm X100VI: current delivery estimates and the best retailers alex.whitelock@f...
Apple expands Business Connect tools to help firms stay in touch with customers | usagoldmines.com
9 must-know details about Windows 11’s big 2024 update | usagoldmines.com
Arm wants to go direct Chinese market, no more ArmChina middleman | usagoldmines.com
OnePlus shares release date for Android 15 update, announces new AI features jamie.richards@futurene...
Google says it has made big steps in improving memory safety | usagoldmines.com
Joe Rogan says the Garmin Fenix 8's cold water problem "sucks" – but he's got a solution matt.evans@...
Netflix teases Virgin River season 6's wedding of the year and I desperately need an invite grace.mo...
Proton unveils new business VPN features benedict.collins@futurenet.com (Benedict Collins) | usagold...
Finally upgrading from isc-dhcp-server to isc-kea for my homelab Lee Hutchinson | usagoldmines.com
Rocket Report: Bloomberg calls for SLS cancellation; SpaceX hits century mark Eric Berger | usagoldm...
Simple voltage pulse can restore capacity to Li-Si batteries John Timmer | usagoldmines.com
You’re not alone – many users are reporting iPhone 16 battery life issues on iOS 18 | usagoldmines....
Don't panic, Facer users, full Wear OS 5 support is coming – eventually stephen.warwick@futurenet.co...
Nvidia is killing off its Control Panel app - and it wants you to help shape its replacement | usag...
Dbrand has returned with new Darkplates 2.0 - bespoke face plates you can put on your PS5 Slim | us...
Looking at buying an SSD? Hold fire for now – prices are predicted to drop (and on top of that, Blac...
Leaked dummy units of all three Samsung Galaxy S25 phones show off their sizes and dimensions | usa...
Navigating the AI skills shortage: Strategies for global CIOs | usagoldmines.com
ChatGPT app comes to Windows finally! Add a quick AI shortcut to your PC today john-anthony.disotto@...
Business heads are struggling to trust AI, but hope it will be a major source of revenue | usagoldm...
Lowest price ever for this Microsoft must-have for programmers | usagoldmines.com
How did we live without this 1TB dual USB-C + USB-A flash drive? | usagoldmines.com
Building in security without putting the brakes on application development | usagoldmines.com
Almost all executives think their IT is best-in-class, but ‘future ready’ is a different story | us...
Meta's AI chief is right to call AI fearmongering 'BS' but not for the reason he thinks erichs211@gm...
Apple Pay added new ways to pay, like card rewards and installment plans jacob.krol@futurenet.com (J...
11 Halloween Movies That Aren't Too Scary to Watch With Your Kids Stephen Johnson | usagoldmines.com
My favorite Apple TV Plus comedy Shrinking has been renewed for season 3, and it's exactly what the ...
A solution in search of a problem? Intel debuts AI app that runs locally on its most recent CPUs - b...
Biden administration curtails controls on some space-related exports Stephen Clark | usagoldmines.co...
Best VPNs for torrenting 2024: Speed, privacy, and security matter | usagoldmines.com
The Best Ways to Keep Your Drafty House Warm in the Winter Lindsey Ellefson | usagoldmines.com
Nine of the Best Halloween Specials to Watch With Your Kids Stephen Johnson | usagoldmines.com
iPhone 16 Users Complain About Excessive iOS 18 Battery Drain Juli Clover | usagoldmines.com
Price of world's largest SSD has nearly doubled since launch - could extreme demand for AI servers a...
How to give your favorite pictures and videos an AI-written soundtrack erichs211@gmail.com (Eric Hal...
Having issues with macOS Sequoia pop-ups? Apple is working on it but there’s a fix now allisa.james@...
Amazon just dropped the Fire TV Stick HD, and it comes with a nice surprise in the box jacob.krol@fu...
NYT Strands today — hints, answers and spangram for Friday, October 18 (game #229) marc.mclaren@futu...
Quordle today – hints and answers for Friday, October 18 (game #998) marc.mclaren@futurenet.com (Mar...
NYT Connections today — hints and answers for Friday, October 18 (game #495) marc.mclaren@futurenet....
Cheap AI “video scraping” can now extract data from any screen recording Benj Edwards | usagoldmines...
Qualcomm cancels Windows dev kit PC for “comprehensively” failing to meet standards Andrew Cunningha...
23andMe Might Owe You Some Money Jake Peterson | usagoldmines.com
Here Are the Best Deals on the New iPad Mini 7 Daniel Oropeza | usagoldmines.com
Apple Preparing to Add ChatGPT Integration to Siri Juli Clover | usagoldmines.com
Redbox easily reverse-engineered to reveal customers’ names, zip codes, rentals Scharon Harding | us...
The Sisterhood faces a powerful foe in Dune: Prophecy trailer Jennifer Ouellette | usagoldmines.com
Best PC computer deals: Top picks from desktops to all-in-ones | usagoldmines.com
How to Know If You Need a Whooping Cough Vaccine As Cases Rise Beth Skwarecki | usagoldmines.com
Google Is Cracking Down on Ad Blockers, But Here's How You Can Fight Back Michelle Ehrhardt | usagol...
My Favorite Firefox Extensions for Android Pranay Parab | usagoldmines.com
My Favorite Amazon Deal of the Day: The Samsung Galaxy Ring Daniel Oropeza | usagoldmines.com
Apple TV+ to Offer Behind-the-Scenes Coverage of 2024 World Series Joe Rossignol | usagoldmines.com
US vaccinations fall again as more parents refuse lifesaving shots for kids Beth Mole | usagoldmines...
How the Malleus maleficarum fueled the witch trial craze Jennifer Ouellette | usagoldmines.com
Google Sold a Bunch of Pixel 9 Phones, Possibly a Record High Kellen | usagoldmines.com
How to Cancel a Subscription Online Even When the Company Doesn’t Want You To Jake Peterson | usagol...
You Should Report Companies That Make It Harder to Cancel Than to Sign Up Jake Peterson | usagoldmin...
Apple Pay Chief Suggests Digital Car Keys Could Expand to Rentals Juli Clover | usagoldmines.com
New insights into the Sun's corona emerge from the first successful detailed magnetic field measurem...
Here’s how SIM swap in alleged bitcoin pump-and-dump scheme worked Dan Goodin | usagoldmines.com
Best laptops for video editing 2024: Work faster with these expert picks | usagoldmines.com
Motorola Phones Getting Circle to Search Tim | usagoldmines.com
China cyber pros say Intel is installing CPU backdoors on behalf of NSA benedict.collins@futurenet.c...
Artemis II almost certainly will miss its September 2025 launch date Eric Berger | usagoldmines.com
OLED monitors are the hot new display trend, report says | usagoldmines.com
Tiny 11 can shrink Windows 11 24H2 disk space requirement by over 80% | usagoldmines.com
Revamped Microsoft Store page experience coming to Windows 11 ‘soon’ | usagoldmines.com
Why Your Credit History Is More Important Than Your Credit Score Meredith Dietz | usagoldmines.com
Prepare Now so the End of Daylight Saving Time Is Less Jarring Beth Skwarecki | usagoldmines.com
Five Ways You Can Lose Your Social Security Benefits Jeff Somers | usagoldmines.com
What's New on Hulu in November 2024 Emily Long | usagoldmines.com
Apple Music Now Lets Artists Create Playlists Based on Concert Set Lists Joe Rossignol | usagoldmine...
Developers Now Required to Share Phone Number and Address on EU App Store to Meet 'Trader' Requireme...
DDoS cybercriminals who hit big tech and FBI charged by US | usagoldmines.com
The Microsoft Store get new tweaks and tricks - but I wonder if it'll get Windows 11 users to care ...
Google Flights will now let you prioritize super-cheap flights over convenience hamish.hector@future...
Sony's best headphones and earbuds just got a free update with new features – including one we've be...
Hundreds of thousands of CVs leaked - here's what we know | usagoldmines.com
Google’s AI podcast generator NotebookLM just got a major update – and now you can play the producer...
Netflix releases two trailers for surprisingly spooky animations – including our first look at the n...

Leave a Reply