A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process. Virtual machine images built using the Proxmox provider do not disable these default credentials, and nodes using the resulting images may be accessible via these default credentials. The credentials can be used to gain root access. Kubernetes clusters are only affected if their nodes use VM images created via the Image Builder project with its Proxmox provider.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-3002 A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process. Virtual machine images built using the Proxmox provider do not disable these default credentials, and nodes using the resulting images may be accessible via these default credentials. The credentials can be used to gain root access. Kubernetes clusters are only affected if their nodes use VM images created via the Image Builder project with its Proxmox provider.
Github GHSA Github GHSA GHSA-9224-ggvw-wh7v VM images built with Image Builder and Proxmox provider use default credentials in github.com/kubernetes-sigs/image-builder
Fixes

Solution

Rebuild any affected images using a fixed version of Image Builder. Re-deploy the fixed images to any affected VMs.


Workaround

Prior to upgrading, this vulnerability can be mitigated by disabling the builder account on affected VMs: usermod -L builder

History

Tue, 09 Dec 2025 04:00:00 +0900

Type Values Removed Values Added
First Time appeared Kubernetes-sigs
Kubernetes-sigs image Builder
CPEs cpe:2.3:a:kubernetes-sigs:image_builder:*:*:*:*:*:*:*:*
Vendors & Products Kubernetes-sigs
Kubernetes-sigs image Builder

Fri, 11 Jul 2025 22:45:00 +0900

Type Values Removed Values Added
Metrics epss

{'score': 0.0059}

epss

{'score': 0.00605}


Thu, 29 May 2025 01:45:00 +0900

Type Values Removed Values Added
References

Thu, 22 May 2025 11:30:00 +0900


Thu, 17 Oct 2024 10:15:00 +0900

Type Values Removed Values Added
Weaknesses CWE-1392
References
Metrics threat_severity

None

threat_severity

Critical


Thu, 17 Oct 2024 04:15:00 +0900

Type Values Removed Values Added
First Time appeared Kubernetes
Kubernetes image Builder
CPEs cpe:2.3:a:kubernetes:image_builder:*:*:*:*:*:*:*:*
Vendors & Products Kubernetes
Kubernetes image Builder
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Oct 2024 05:45:00 +0900

Type Values Removed Values Added
Description A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process. Virtual machine images built using the Proxmox provider do not disable these default credentials, and nodes using the resulting images may be accessible via these default credentials. The credentials can be used to gain root access. Kubernetes clusters are only affected if their nodes use VM images created via the Image Builder project with its Proxmox provider.
Title VM images built with Image Builder and Proxmox provider use default credentials
Weaknesses CWE-798
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: kubernetes

Published:

Updated: 2024-10-16T18:56:40.632Z

Reserved: 2024-10-03T16:33:36.995Z

Link: CVE-2024-9486

cve-icon Vulnrichment

Updated: 2024-10-16T18:56:10.486Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-15T21:15:11.573

Modified: 2025-12-08T18:51:50.370

Link: CVE-2024-9486

cve-icon Redhat

Severity : Critical

Publid Date: 2024-10-16T18:03:32Z

Links: CVE-2024-9486 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses