Security Flaw in Kubernetes Image Builder Affects Nodes Using Nutanix and OVA Providers
CVE-2025-7342
What is CVE-2025-7342?
A security issue has been identified in the Kubernetes Image Builder where default credentials are inadvertently enabled during the image build process. This vulnerability impacts virtual machine images created using the Nutanix or OVA provider, allowing potential unauthorized access through these default credentials. Nodes utilizing the resultant images may become vulnerable, with implications for systems that rely on Kubernetes clusters featuring Windows nodes. The exposure of default credentials could lead to unauthorized root access, posing significant security risks to affected infrastructures.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Image Builder 0 <= 0.1.44
Image Builder 0.1.45
References
CVSS V3.1
Timeline
Vulnerability published