openwall.com
http://www.openwall.com/lists/oss-security/2025/01/16/1 CVE-2024-9042
MEDIUM
Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API
Record summary
CVE-2024-9042 has a selected CVSS score of 5.9 (medium).
Description
This CVE affects only Windows worker nodes. Your worker node is vulnerable to this issue if it is running one of the affected versions listed below.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 13, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
KubeletBrowse Kubernetes / KubeletDefault status: unaffected | CVE List | <=v1.29.12 | affected |
| v1.30 to ≤ v1.30.8 | affected | ||
| v1.31 to ≤ v1.31.4 | affected | ||
| v1.32 to ≤ v1.32.0 | affected | ||
k8s.io/kubernetesBrowse Go / k8s.io/kubernetes | GitHub Advisory | Before 1.29.13 · Fixed in 1.29.13 | affected |
| 1.30.0-alpha.0 to < 1.30.9 · Fixed in 1.30.9 | affected | ||
| 1.31.0-alpha.0 to < 1.31.5 · Fixed in 1.31.5 | affected | ||
| 1.32.0-alpha.0 to < 1.32.1 · Fixed in 1.32.1 | affected |
References
9github.com
https://github.com/kubernetes/kubernetes github.com
https://github.com/kubernetes/kubernetes/commit/45f4ccc2153bbb782253704cbe24c05e22b5d60c github.com
https://github.com/kubernetes/kubernetes/commit/5fe148234f8ab1184f26069c4f7bef6c37efe347 github.com
https://github.com/kubernetes/kubernetes/commit/75c83a6871dc030675288c6d63c275a43c2f0d55 github.com
https://github.com/kubernetes/kubernetes/commit/fb0187c2bf7061258bb89891edb1237261eb7abc github.com
https://github.com/kubernetes/kubernetes/issues/129654 groups.google.com
https://groups.google.com/g/kubernetes-security-announce/c/9C3vn6aCSVg nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-9042