Use of default credentials in image-builder - CVE-2024-9594

 

Use of default credentials in image-builder - CVE-2024-9594

Published: October 17, 2024


Vulnerability identifier: #VU98764
CSH Severity: Medium
CVSS v4: 7.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-9594
CWE-ID: CWE-1392
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the image build process.

The vulnerability exists due to default credentials are enabled during the image build process when using the Nutanix, OVA, QEMU or raw providers. A remote attacker with ability to reach the VM where the image build was happening can compromise the image during its build.


Affected software

image-builder

How to mitigate CVE-2024-9594

Install updates from vendor's website.

image-builder - update to 0.1.38

External References

Related Security Bulletins