CVE-2024-10220

Aliases:GHSA-27wf-5967-98gxGO-2024-3286DEBIAN-CVE-2024-10220CGA-297g-3qmg-4h9fCGA-37qq-98r3-cfgpCGA-3pjx-5v87-vc7rCGA-47qc-q732-9w75CGA-4w32-pvrx-68hxCGA-59mf-h7wm-r8g6CGA-73c3-vq64-j4q9CGA-7c8x-rjhq-96w7CGA-7g6m-9pf3-r5qmCGA-7gqj-5fvx-86vqCGA-7wmx-2mpv-vw59CGA-837f-jh72-8338CGA-88r3-fpqm-25p6CGA-9fgr-3rwc-m82hCGA-9qcx-j8g6-6hp6CGA-9v53-9xq2-9vggCGA-c4m5-qpm9-qr6vCGA-cmj5-v3cg-j76rCGA-cphq-2c6w-m2vxCGA-fjfj-3fgg-xjg8CGA-fmq7-7pv8-73prCGA-fp6p-hhpp-gjpcCGA-g835-7f82-5v3gCGA-h63m-3qc4-2687CGA-hfgp-8pvc-v26wCGA-j2fp-j44q-5qmwCGA-m4v4-4xxc-9j8jCGA-m7jj-hhqq-rg8gCGA-mc3j-vhm9-cfv3CGA-p9v3-f9w2-vr5gCGA-pgw6-7r5x-rh3mCGA-34mx-6mc7-932gCGA-3wmq-9g2q-cp8qCGA-4jh6-fhj9-qxgqCGA-525m-c62x-v2mjCGA-56hm-rq6m-g533CGA-6xwc-344r-x3w4CGA-733w-3mjw-4xvpCGA-9hqm-8hhp-w5j5CGA-9jgr-w9vx-9v6wCGA-9qg6-9r92-jmcjCGA-9v5w-w794-qx29CGA-cm7r-gmv7-76pjCGA-f26f-gr35-2j87CGA-f3qf-rv83-g93jCGA-g7mj-v5gv-wxw5CGA-h25p-c6rm-x289CGA-hf9p-v2fc-9939CGA-j9rm-m929-mqxcCGA-q259-v24p-x99rCGA-qh96-5872-8c4hCGA-qhxv-7ff8-wrcgCGA-qv7v-7787-jq69CGA-r2c4-34j3-9332CGA-r324-p326-pwq7CGA-v4x9-37p6-hg95CGA-v9g9-5m9j-6c49CGA-vgj9-5f86-3xjhCGA-vp42-hx8p-hwwvCGA-w648-343j-5gfgCGA-w7qm-v35c-8rw5CGA-wf38-j927-p4cvCGA-whp5-9cc4-9fw4CGA-wm3g-q8m2-w5vpCGA-wq27-fw5r-2394CGA-wr5r-xxrg-f433CGA-wv6g-49jc-q84pCGA-xjg2-88q7-j65r
Advisory lineage Upstream: 0 Downstream: 4
Deferred
Published: 22 Nov 2024, 16:23
Last modified:25 Nov 2024, 18:22

Vulnerability Summary

Overall Risk (default)
medium
33/100
CVSS Score
8.1 HIGH
v3.1 (cve.org)
EPSS Score
3.03% LOW
3% probability -24.30%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

22 Nov 2024, 16:23
Published
Vulnerability first disclosed
25 Nov 2024, 18:22
Last Modified
Vulnerability information updated

Description

The Kubernetes kubelet component allows arbitrary command execution via specially crafted gitRepo volumes.This issue affects kubelet: through 1.28.11, from 1.29.0 through 1.29.6, from 1.30.0 through 1.30.2.

CVSS Metrics

  • v4.0HIGHScore: 8.6CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
  • v3.1HIGHScore: 8.1CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

EPSS Trends

Current EPSS score: 3.03% Percentile: 87%

Techniques & Countermeasures

  • CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Affected Systems

  • chainguardargo-cd-2.11

    all

  • chainguardargocd-image-updater

    < 0.17.0-r1

  • chainguardargocd-image-updater-fips

    < 0.17.0-r2

  • chainguardaws-efs-csi-driver

    < 2.1.2-r0

  • chainguardaws-efs-csi-driver-fips

    < 2.1.2-r0

  • chainguardgpu-feature-discovery

    < 0.8.2-r6

  • chainguardip-masq-agent

    < 2.12.0-r0

  • chainguardkubeflow-pipelines

    < 2.3.0-r3

  • chainguardkubeflow-pipelines-apiserver

    < 2.3.0-r3

  • chainguardkubeflow-pipelines-cache_server

    < 2.3.0-r3

  • chainguardkubeflow-pipelines-cache-deployer

    < 2.3.0-r3

  • chainguardkubeflow-pipelines-cache-deployer-compat

    < 2.3.0-r3

  • chainguardkubeflow-pipelines-frontend

    < 2.3.0-r3

  • chainguardkubeflow-pipelines-metadata-envoy-config

    < 2.3.0-r3

  • chainguardkubeflow-pipelines-metadata-writer

    < 2.3.0-r3

  • chainguardkubeflow-pipelines-metadata-writer-compat

    < 2.3.0-r3

  • chainguardkubeflow-pipelines-persistence_agent

    < 2.3.0-r3

  • chainguardkubeflow-pipelines-scheduledworkflow

    < 2.3.0-r3

  • chainguardkubeflow-pipelines-viewer-crd-controller

    < 2.3.0-r3

  • chainguardkubernetes-dns-node-cache

    < 1.23.1-r5

  • chainguardkubernetes-dns-node-cache-fips

    < 1.23.1-r4

  • chainguardlocal-static-provisioner

    < 2.7.0-r8

  • chainguardlocal-static-provisioner-compat

    < 2.7.0-r8

  • chainguardlocal-static-provisioner-fips

    < 2.7.0-r1

  • chainguardlocal-static-provisioner-fips-compat

    < 2.7.0-r1

  • chainguardlocal-volume-node-cleanup

    < 2.7.0-r8

  • chainguardlocal-volume-node-cleanup-compat

    < 2.7.0-r8

  • chainguardlocal-volume-node-cleanup-fips

    < 2.7.0-r1

  • chainguardlocal-volume-node-cleanup-fips-compat

    < 2.7.0-r1

  • chainguardnodetaint

    < 0.0.4-r23

  • chainguardrancher-webhook-0.4

    < 0.4.18-r2

  • chainguardrancher-webhook-0.5

    < 0.5.12-r17

  • chainguardrancher-webhook-fips-0.4

    < 0.4.18-r4

  • chainguardrancher-webhook-fips-0.5

    < 0.5.11-r0

  • wolfiargocd-image-updater

    < 0.17.0-r1

  • wolfiaws-efs-csi-driver

    < 2.1.2-r0

  • wolfigpu-feature-discovery

    < 0.8.2-r6

  • wolfiip-masq-agent

    < 2.12.0-r0

  • wolfikubeflow-pipelines

    < 2.3.0-r3

  • wolfikubeflow-pipelines-apiserver

    < 2.3.0-r3

  • wolfikubeflow-pipelines-cache_server

    < 2.3.0-r3

  • wolfikubeflow-pipelines-cache-deployer

    < 2.3.0-r3

  • wolfikubeflow-pipelines-cache-deployer-compat

    < 2.3.0-r3

  • wolfikubeflow-pipelines-frontend

    < 2.3.0-r3

  • wolfikubeflow-pipelines-metadata-envoy-config

    < 2.3.0-r3

  • wolfikubeflow-pipelines-metadata-writer

    < 2.3.0-r3

  • wolfikubeflow-pipelines-metadata-writer-compat

    < 2.3.0-r3

  • wolfikubeflow-pipelines-persistence_agent

    < 2.3.0-r3

  • wolfikubeflow-pipelines-scheduledworkflow

    < 2.3.0-r3

  • wolfikubeflow-pipelines-viewer-crd-controller

    < 2.3.0-r3

Showing first 50 affected entries in server-rendered view.

References (10)