HIGH 8.1 Go

Kubernetes kubelet arbitrary command execution

GHSA-27wf-5967-98gx · CVE-2024-10220 · GO-2024-3286

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

The Kubernetes kubelet component allows arbitrary command execution via specially crafted gitRepo volumes.This issue affects kubelet: through 1.28.11, from 1.29.0 through 1.29.6, from 1.30.0 through 1.30.2.

Ready to move

Start Securing

Free, no credit card | First findings in minutes