Security Flaw in Kubernetes Image Builder Affects Nodes Using Nutanix and OVA Providers
CVE-2025-7342

7.5HIGH

Key Information:

Vendor

Kubernetes

Vendor
CVE Published:
17 August 2025

What is CVE-2025-7342?

A security issue has been identified in the Kubernetes Image Builder where default credentials are inadvertently enabled during the image build process. This vulnerability impacts virtual machine images created using the Nutanix or OVA provider, allowing potential unauthorized access through these default credentials. Nodes utilizing the resultant images may become vulnerable, with implications for systems that rely on Kubernetes clusters featuring Windows nodes. The exposure of default credentials could lead to unauthorized root access, posing significant security risks to affected infrastructures.

Affected Version(s)

Image Builder 0 <= 0.1.44

Image Builder 0.1.45

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.