Input validation error in Kubelet - CVE-2024-10220

 

Input validation error in Kubelet - CVE-2024-10220

Published: December 13, 2024 / Updated: September 12, 2025


Vulnerability identifier: #VU101778
CSH Severity: Medium
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N]
CVE-ID: CVE-2024-10220
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary commands on the system.

The vulnerability exists due to an error when handling gitRepo volumes. A remote user with the ability to create a pod and associate a gitRepo volume can execute arbitrary commands beyond the container boundary.


Affected software

Kubelet
Guardium Data Security Center (GDSC)
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
IBM Cloud Pak for Watson AIOps
openEuler
Anolis OS
kubernetes-client
kubernetes-help
kubernetes-kubeadm
kubernetes-kubelet
kubernetes-master
kubernetes-node
kubernetes
IBM InfoSphere Information Server
IBM InfoSphere Information Server for Cloud

How to mitigate CVE-2024-10220

Install updates from vendor's website.

Kubelet - addressed in versions 1.28.12, 1.29.7, 1.30.3
Guardium Data Security Center (GDSC) - update to 3.7.2
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.3
kubernetes-client - update to 1.20.2-26
kubernetes-help - update to 1.20.2-26
kubernetes-kubeadm - update to 1.20.2-26
kubernetes-kubelet - update to 1.20.2-26
kubernetes-master - update to 1.20.2-26
kubernetes-node - update to 1.20.2-26
kubernetes - update to 1.20.2-26
kubernetes-node - update to 1.27.8-3
kubernetes - update to 1.27.8-3
kubernetes-client - update to 1.27.8-3
kubernetes-kubeadm - update to 1.27.8-3
kubernetes-master - update to 1.27.8-3
IBM Cloud Pak for Watson AIOps - update to 4.8.1
IBM InfoSphere Information Server - update to 11.7.1 Fix Pack 6
IBM InfoSphere Information Server for Cloud - update to 11.7.1 Fix Pack 6

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins