CVE-2024-10220: Kubernetes Kubelet

High severity, CVSS 8.1. EPSS: 3% chance of exploitation in the next 30 days.

The Kubernetes kubelet component allows arbitrary command execution via specially crafted gitRepo volumes.This issue affects kubelet: through 1.28.11, from 1.29.0 through 1.29.6, from 1.30.0 through 1.30.2.

Affected products

  • Kubernetes Kubelet: up to and including 1.28.11; from 1.29.0, up to and including 1.29.6; from 1.30.0, up to and including 1.30.2

Published 2024-11-22. Last modified 2026-06-17.