CVE-2024-10220: Arbitrary command execution through gitRepo volume
Arbitrary command execution through gitRepo volume
Other sources
The Kubernetes kubelet component allows arbitrary command execution via specially crafted gitRepo volumes.This issue affects kubelet: through 1.28.11, from 1.29.0 through 1.29.6, from 1.30.0 through 1.30.2.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10220?
CVE-2024-10220 has a critical severity due to its potential for arbitrary command execution.
How do I fix CVE-2024-10220?
To resolve CVE-2024-10220, upgrade kubelet to version 1.30.3 or 1.29.7, or apply the patch in version 1.28.12.
Which versions of kubelet are affected by CVE-2024-10220?
CVE-2024-10220 affects kubelet versions through 1.28.11, and from 1.29.0 to 1.29.6, and from 1.30.0 to 1.30.2.
What are the risks associated with CVE-2024-10220?
The risks of CVE-2024-10220 include unauthorized access and control over system resources through command execution.
Is there a workaround for CVE-2024-10220?
Currently, the best mitigation for CVE-2024-10220 is to upgrade to the recommended versions, as no specific workaround is provided in the advisory.