CVE-2024-9042: [kubernetes] CVE-2024-9042: Command Injection affecting Windows nodes via nodes/*/logs/query API
A security vulnerability has been discovered in Kubernetes windows nodes that could allow a user with the ability to query a node's '/logs' endpoint to execute arbitrary commands on the host. This CVE affects only Windows worker nodes. Your worker node is vulnerable to this issue if it is running one of the affected versions listed below.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9042?
CVE-2024-9042 has a high severity rating as it allows arbitrary command execution on Windows worker nodes.
How do I fix CVE-2024-9042?
To fix CVE-2024-9042, upgrade your Kubernetes Windows nodes to version 1.32.1 or later.
Which Kubernetes versions are affected by CVE-2024-9042?
CVE-2024-9042 affects versions of Kubernetes prior to 1.32.1 on Windows worker nodes.
What kind of systems are impacted by CVE-2024-9042?
CVE-2024-9042 impacts only Windows worker nodes within a Kubernetes deployment.
Who is at risk of CVE-2024-9042?
Users with the ability to query a node's '/logs' endpoint on a vulnerable Windows worker node are at risk of CVE-2024-9042.