Security Flaw in Kubernetes Image Builder Affects Nodes Using Nutanix and OVA Providers
CVE-2025-7342

Currently unrated

Key Information:

Vendor

Kubernetes

Vendor
CVE Published:
17 August 2025

What is CVE-2025-7342?

A security issue has been identified in the Kubernetes Image Builder where default credentials are inadvertently enabled during the image build process. This vulnerability impacts virtual machine images created using the Nutanix or OVA provider, allowing potential unauthorized access through these default credentials. Nodes utilizing the resultant images may become vulnerable, with implications for systems that rely on Kubernetes clusters featuring Windows nodes. The exposure of default credentials could lead to unauthorized root access, posing significant security risks to affected infrastructures.

References

Timeline

  • Vulnerability published

.
CVE-2025-7342 : Security Flaw in Kubernetes Image Builder Affects Nodes Using Nutanix and OVA Providers