CNCF K3s Kubernetes kubelet configuration exposes credentials
Moderate severity
GitHub Reviewed
Published
Apr 25, 2025
to the GitHub Advisory Database
•
Updated Apr 25, 2025
Package
Affected versions
>= 1.32.0-rc1, < 1.32.4-rc1
Patched versions
1.32.4-rc1
Description
Published by the National Vulnerability Database
Apr 25, 2025
Published to the GitHub Advisory Database
Apr 25, 2025
Reviewed
Apr 25, 2025
Last updated
Apr 25, 2025
CNCF K3s 1.32 before 1.32.4-rc1+k3s1 has a Kubernetes kubelet configuration change with the unintended consequence that, in some situations, ReadOnlyPort is set to 10255. For example, the default behavior of a K3s online installation might allow unauthenticated access to this port, exposing credentials.
References