CyberRota Analysis
AI-GeneratedThe KubeEdge NodeUpgradeJob handler is vulnerable to command injection due to improper handling of user-controlled input in the spec.version and spec.image fields, allowing an authenticated user to execute arbitrary commands on edge nodes. This vulnerability can lead to a compromise of node confidentiality, integrity, and availability, making it critical for organizations using KubeEdge versions 1.12.0 through 1.23.1 to prioritize upgrading to the patched versions 1.21.2, 1.22.2, or 1.23.1. Users with permissions to create or update NodeUpgradeJob resources should be particularly vigilant.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.12.0 until 1.21.2, 1.22.2, and 1.23.1, the v1alpha2 NodeUpgradeJob handler in edge/pkg/taskmanager/actions/nodeupgradejob.go concatenates authenticated user-controlled spec.version and spec.image values into the keadm upgrade edge shell command. A user with permission to create or update NodeUpgradeJob resources can supply shell metacharacters in either field, causing arbitrary commands to execute on targeted edge nodes with the privileges of the upgrade process and compromising node confidentiality, integrity, and availability. This issue is fixed in versions 1.21.2, 1.22.2, and 1.23.1.