{"id":"GO-2024-3286","summary":"Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes","details":"Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes","aliases":["CVE-2024-10220","GHSA-27wf-5967-98gx"],"modified":"2026-03-17T04:49:25.589277Z","published":"2024-11-27T19:16:39Z","related":["CGA-qv2r-m637-rw2f"],"database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2024-3286"},"references":[{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-27wf-5967-98gx"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2024/11/20/1"},{"type":"WEB","url":"https://github.com/kubernetes/kubernetes/commit/1ab06efe92d8e898ca1931471c9533ce94aba29b"},{"type":"WEB","url":"https://github.com/kubernetes/kubernetes/issues/128885"},{"type":"WEB","url":"https://groups.google.com/g/kubernetes-security-announce/c/ptNgV5Necko"}],"affected":[{"package":{"name":"k8s.io/kubernetes","ecosystem":"Go","purl":"pkg:golang/k8s.io/kubernetes"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.28.12"},{"introduced":"1.29.0"},{"fixed":"1.29.7"},{"introduced":"1.30.0"},{"fixed":"1.30.3"}]}],"ecosystem_specific":{"imports":[{"symbols":["validateVolume"],"path":"k8s.io/kubernetes/pkg/volume/git_repo"}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2024-3286.json"}}],"schema_version":"1.7.5"}