Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2024-9042: Command Injection affecting Windows nodes via nodes/*/logs/query API #4752

Open
kaarthis opened this issue Jan 16, 2025 · 1 comment
Assignees

Comments

@kaarthis
Copy link
Contributor

kaarthis commented Jan 16, 2025

More here : kubernetes/kubernetes#129654

Essentially this CVE impacts the kubelet feature "NodeLogQuery", which is not enabled on AKS clusters, hence there is no direct risk for existing Windows node pools. The fix has been backported to supported Kubernetes versions and will be available soon

@bcho bcho changed the title Command Injection affecting Windows nodes via nodes/*/logs/query API CVE-2024-9042: Command Injection affecting Windows nodes via nodes/*/logs/query API Jan 16, 2025
Copy link
Contributor

This issue has been automatically marked as stale because it has not had any activity for 21 days. It will be closed if no further activity occurs within 7 days of this comment.

@microsoft-github-policy-service microsoft-github-policy-service bot added the stale Stale issue label Feb 6, 2025
@sjwaight sjwaight removed the stale Stale issue label Feb 6, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants