CVE-2024-10220
HIGHKubernetes <1.28.11, 1.29.0-1.29.6, 1.30.0-1.30.2 - Command Injection
Title source: llmDescription
The Kubernetes kubelet component allows arbitrary command execution via specially crafted gitRepo volumes.This issue affects kubelet: through 1.28.11, from 1.29.0 through 1.29.6, from 1.30.0 through 1.30.2.
Exploits (8)
nomisec
WRITEUP
1 stars
by mrk336 · poc
https://github.com/mrk336/CVE-2024-10220-Kubernetes-gitRepo-Volume-Vulnerability
nomisec
WORKING POC
1 stars
by mochizuki875 · poc
https://github.com/mochizuki875/CVE-2024-10220-githooks
nomisec
NO CODE
by saleha-muzammil · poc
https://github.com/saleha-muzammil/cve-2024-10220-git-on-git
Scores
CVSS v3
8.1
EPSS
0.3957
EPSS Percentile
97.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Details
CWE
CWE-22
Status
published
Products (8)
k8s.io/kubernetes
0 - 1.28.12Go
Kubernetes/kubelet
< 1.28.11
Kubernetes/kubelet
1.28.12
Kubernetes/kubelet
1.29.0 - 1.29.6
Kubernetes/kubelet
1.29.7
Kubernetes/kubelet
1.30.0 - 1.30.2
Kubernetes/kubelet
1.30.3
Kubernetes/kubelet
1.31.0
Published
Nov 22, 2024
Tracked Since
Feb 18, 2026