Launch Week Day 1: Announcing Security Design Review
HIGH 8.1 Go

Kubernetes kubelet arbitrary command execution

GHSA-27wf-5967-98gx · CVE-2024-10220 · GO-2024-3286

Published · Modified

Description

The Kubernetes kubelet component allows arbitrary command execution via specially crafted gitRepo volumes.This issue affects kubelet: through 1.28.11, from 1.29.0 through 1.29.6, from 1.30.0 through 1.30.2.

Ready to move

Start Securing

Free, no credit card | First findings in minutes