CyberRota Analysis
AI-GeneratedKubeEdge versions 1.21.0 to 1.21.2, 1.22.2, and 1.23.1 are vulnerable due to improper handling of user-controlled input in the ConfigUpdateJob processing, allowing authenticated users to inject shell metacharacters and execute arbitrary commands on target edge nodes. This vulnerability poses a high risk as it can lead to unauthorized command execution with the privileges of the KubeEdge process. Organizations utilizing affected versions should prioritize patching to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.21.0 until 1.21.2, 1.22.2, and 1.23.1, ConfigUpdateJob processing in edge/pkg/taskmanager/actions/configupdatejob.go concatenates authenticated user-controlled updateFields values into the keadm config-update command and executes it through a system shell. A user with permission to create or modify ConfigUpdateJob resources can include shell metacharacters in the complete --set value and cause arbitrary commands to execute on an enrolled target edge node with the privileges of the KubeEdge process handling the job. This issue is fixed in versions 1.21.2, 1.22.2, and 1.23.1.