This CVE affects only Windows worker nodes. Your worker node is vulnerable to this issue if it is running one of the affected versions listed below.
Metrics
Affected Vendors & Products
References
History
Thu, 13 Mar 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 13 Mar 2025 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Thu, 13 Mar 2025 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A flaw was found in Kubernetes Windows nodes. This vulnerability allows a user with the ability to query a node's '/logs' endpoint to execute arbitrary commands on the host. | This CVE affects only Windows worker nodes. Your worker node is vulnerable to this issue if it is running one of the affected versions listed below. |
Weaknesses | CWE-20 | |
References |
|
Thu, 16 Jan 2025 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A flaw was found in Kubernetes Windows nodes. This vulnerability allows a user with the ability to query a node's '/logs' endpoint to execute arbitrary commands on the host. | |
Title | kubelet: Command Injection affecting Windows nodes via nodes/*/logs/query API | |
Weaknesses | CWE-78 | |
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|

Status: PUBLISHED
Assigner: kubernetes
Published: 2025-03-13T16:40:13.895Z
Updated: 2025-03-13T19:24:39.825Z
Reserved: 2024-09-20T10:02:50.891Z
Link: CVE-2024-9042

Updated: 2025-03-13T17:02:40.910Z

Status : Received
Published: 2025-03-13T17:15:34.277
Modified: 2025-03-13T17:15:34.277
Link: CVE-2024-9042
