Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54053 | This CVE affects only Windows worker nodes. Your worker node is vulnerable to this issue if it is running one of the affected versions listed below. |
Github GHSA |
GHSA-vv39-3w5q-974q | Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 17 Jun 2025 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:windows_machine_config:10.16::el9 |
Tue, 10 Jun 2025 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat windows Machine Config |
|
| CPEs | cpe:/a:redhat:windows_machine_config:10.17::el9 | |
| Vendors & Products |
Redhat
Redhat windows Machine Config |
Thu, 13 Mar 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Mar 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 13 Mar 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Kubernetes Windows nodes. This vulnerability allows a user with the ability to query a node's '/logs' endpoint to execute arbitrary commands on the host. | This CVE affects only Windows worker nodes. Your worker node is vulnerable to this issue if it is running one of the affected versions listed below. |
| Weaknesses | CWE-20 | |
| References |
|
Thu, 16 Jan 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Kubernetes Windows nodes. This vulnerability allows a user with the ability to query a node's '/logs' endpoint to execute arbitrary commands on the host. | |
| Title | kubelet: Command Injection affecting Windows nodes via nodes/*/logs/query API | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Status: PUBLISHED
Assigner: kubernetes
Published:
Updated: 2025-03-13T19:24:39.825Z
Reserved: 2024-09-20T10:02:50.891Z
Link: CVE-2024-9042
Updated: 2025-03-13T17:02:40.910Z
Status : Deferred
Published: 2025-03-13T17:15:34.277
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-9042
OpenCVE Enrichment
No data.
EUVD
Github GHSA