« Volver al listado

CVE-2024-9042

Estado: AplazadaMedia (5.9)—

This CVE affects only Windows worker nodes. Your worker node is vulnerable to this issue if it is running one of the affected versions listed below.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-9042",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-9042",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-03-13T19:24:29.055805Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "jordan@liggitt.net",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.9,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 0.7
      }
    ]
  },
  "affected": [
    {
      "source": "jordan@liggitt.net",
      "affectedData": [
        {
          "vendor": "Kubernetes",
          "product": "Kubelet",
          "versions": [
            {
              "status": "affected",
              "version": "<=v1.29.12"
            },
            {
              "status": "affected",
              "version": "v1.30",
              "versionType": "semver",
              "lessThanOrEqual": "v1.30.8"
            },
            {
              "status": "affected",
              "version": "v1.31",
              "versionType": "semver",
              "lessThanOrEqual": "v1.31.4"
            },
            {
              "status": "affected",
              "version": "v1.32",
              "versionType": "semver",
              "lessThanOrEqual": "v1.32.0"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-03-13T17:15:34.277",
  "references": [
    {
      "url": "https://github.com/kubernetes/kubernetes/issues/129654",
      "source": "jordan@liggitt.net"
    },
    {
      "url": "https://groups.google.com/g/kubernetes-security-announce/c/9C3vn6aCSVg",
      "source": "jordan@liggitt.net"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2025/01/16/1",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "jordan@liggitt.net",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "This CVE affects only Windows worker nodes. Your worker node is vulnerable to this issue if it is running one of the affected versions listed below."
    },
    {
      "lang": "es",
      "value": "Esta CVE afecta únicamente a los nodos de trabajo de Windows. Su nodo de trabajo es vulnerable a este problema si ejecuta una de las versiones afectadas que se enumeran a continuación."
    }
  ],
  "lastModified": "2026-06-17T08:23:50.653",
  "sourceIdentifier": "jordan@liggitt.net"
}