Database/Container, Kubernetes & orchestration
Kubernetes (kubelet): Command injection on Windows nodes via the nodes/*/logs/query API
Impact
Command injection on Windows nodes via the nodes/*/logs/query API
Who can reach it
Cluster user with node log-query rights
What to do
Rolling kubelet upgrade; Windows node drain; restrict nodes/log RBAC
Fleet impact
How widespread
Niche in GPU clouds - Windows GPU nodes are rare, but the nodes/*/logs/query path is a reminder that kubelet log endpoints reach the host shell
Cost to remediate
daemon-restart - kubelet upgrade to v1.32.1 / v1.31.5 / v1.30.9 / v1.29.13, node-by-node
Why it hits the whole fleet
Anyone with nodes/*/logs read rights injects into PowerShell and executes as SYSTEM on the node; low ubiquity in GPU fleets keeps this off the emergency list
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.