{"id":"MGASA-2024-0389","summary":"Updated kubernetes packages fix security vulnerabilities","details":"A security issue was discovered in Kubernetes where users may be able to\nlaunch containers that bypass the mountable secrets policy enforced by\nthe ServiceAccount admission plugin when using containers, init\ncontainers, and ephemeral containers with the envFrom field populated.\nThe policy ensures pods running with a service account may only\nreference secrets specified in the service account’s secrets field.\nKubernetes clusters are only affected if the ServiceAccount admission\nplugin and the kubernetes.io/enforce-mountable-secrets annotation are\nused together with containers, init containers, and ephemeral containers\nwith the envFrom field populated. CVE-2024-3177\nThe Kubernetes kubelet component allows arbitrary command execution via\nspecially crafted gitRepo volumes. CVE-2024-10220\n","modified":"2026-03-25T17:45:08.637153Z","published":"2024-12-06T17:09:22Z","related":["CVE-2024-10220","CVE-2024-3177"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2024-0389.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=33143"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=33802"},{"type":"REPORT","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WL54MTLGMTBZZO5PYGEGEBERTMADC4WC/"},{"type":"REPORT","url":"https://www.openwall.com/lists/oss-security/2024/11/20/1"}],"affected":[{"package":{"name":"kubernetes","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/kubernetes?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.27.16-2.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2024-0389.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}