You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Essentially this CVE impacts the kubelet feature "NodeLogQuery", which is not enabled on AKS clusters, hence there is no direct risk for existing Windows node pools. The fix has been backported to supported Kubernetes versions and will be available soon
The text was updated successfully, but these errors were encountered:
bcho
changed the title
Command Injection affecting Windows nodes via nodes/*/logs/query API
CVE-2024-9042: Command Injection affecting Windows nodes via nodes/*/logs/query API
Jan 16, 2025
This issue has been automatically marked as stale because it has not had any activity for 21 days. It will be closed if no further activity occurs within 7 days of this comment.
More here : kubernetes/kubernetes#129654
Essentially this CVE impacts the kubelet feature "NodeLogQuery", which is not enabled on AKS clusters, hence there is no direct risk for existing Windows node pools. The fix has been backported to supported Kubernetes versions and will be available soon
The text was updated successfully, but these errors were encountered: