Azure / Azure/AKS

CVE-2024-9042: Command Injection affecting Windows nodes via nodes/*/logs/query API

Open
#4,752 1 comment 0 reactions 2 assignees Claimed by @bcho View on GitHub
action-required
Dominant language
TypeScript
Stars
2.1k
Forks
395
Avg merge
2d 22h
Merged PRs (30d)
13

Description

More here : https://github.com/kubernetes/kubernetes/issues/129654

Essentially this CVE impacts the kubelet feature "NodeLogQuery", which is not enabled on AKS clusters, hence there is no direct risk for existing Windows node pools. The fix has been backported to supported Kubernetes versions and will be available soon

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.