Database/Container, Kubernetes & orchestration
Kubernetes (kubelet): Command injection on Windows nodes via the nodes/*/logs/query API
Impact
Command injection on Windows nodes via the nodes/*/logs/query API
Who can reach it
Cluster user with node log-query rights
What to do
Rolling kubelet upgrade; Windows node drain; restrict nodes/log RBAC
Fleet impact
How widespread
Niche in GPU clouds - Windows GPU nodes are rare, but the nodes/*/logs/query path is a reminder that kubelet log endpoints reach the host shell
Cost to remediate
daemon-restart - kubelet upgrade to v1.32.1 / v1.31.5 / v1.30.9 / v1.29.13, node-by-node
Why it hits the whole fleet
Anyone with nodes/*/logs read rights injects into PowerShell and executes as SYSTEM on the node; low ubiquity in GPU fleets keeps this off the emergency list
References
Related entries
- Kubernetes (kubelet): Pod writes to its own /etc/hosts unaccounted for in evictionCVE-2020-8557 · Kubernetes (kubelet)Medium
- Kubernetes (kubelet): Container restart runs as uid 0 despite mustRunAsNonRootCVE-2019-11245 · Kubernetes (kubelet)Medium
- Kubernetes (kubelet): Kubelet API DoS, including via the unauthenticated read-only portCVE-2020-8551 · Kubernetes (kubelet)Medium
- Kubernetes (kubelet): Pods with an empty localhost seccomp profile field silently bypass seccomp enforcementCVE-2023-2431 · Kubernetes (kubelet)Low
- Kubernetes (kubelet): subPath volume mount symlink race gives access to host files and directories outside the volumeCVE-2021-25741 · Kubernetes (kubelet)High
- Kubernetes (kubelet): /debug/pprof exposed on the unauthenticated kubelet healthz portCVE-2019-11248 · Kubernetes (kubelet)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.