CVE-2024-10220High· 8.1▾ MidnightPoC availableKubernetes kubelet arbitrary command execution
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 44.6 · likelihood 0.6 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
3.0%
8 GitHub repos (last check)
The Kubernetes kubelet component allows arbitrary command execution via specially crafted gitRepo volumes.This issue affects kubelet: through 1.28.11, from 1.29.0 through 1.29.6, from 1.30.0 through 1.30.2.
k8s.io/kubernetes < 1.28.12k8s.io/kubernetes >= 1.29.0, < 1.29.7k8s.io/kubernetes >= 1.30.0, < 1.30.3Upgrade to a patched release:
k8s.io/kubernetes 1.28.12k8s.io/kubernetes 1.29.7k8s.io/kubernetes 1.30.3Connected by shared product, vendor, weakness, or advisory.
CVE-2024-5321Medium· 6.1Kubernetes sets incorrect permissions on Windows containers logs
CVE-2023-3676High· 8.8Kubernetes privilege escalation vulnerability
CVE-2020-8561Medium· 4.1Confused Deputy in Kubernetes
CVE-2025-1767Medium· 6.5Kubernetes GitRepo Volume Inadvertent Local Repository Access
CVE-2021-25736Medium· 5.8Kube-proxy may unintentionally forward traffic
CVE-2015-7561Low· 3.1Kubernetes in OpenShift3 Access Control Misconfiguration