CVE-2024-10220 is an OS command injection vulnerability in the Kubernetes kubelet handling of deprecated gitRepo volumes. A specially crafted repository can use Git hooks in its hooks directory to cause kubelet to execute attacker-controlled commands outside the container boundary, in the kubelet host context. Affected kubelet versions are through 1.28.11, 1.29.0 through 1.29.6, and 1.30.0 through 1.30.2.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
This repository is a proof-of-concept exploit for CVE-2024-10220, a vulnerability in Kubernetes kubelet's gitRepo volume feature that allows arbitrary command execution on cluster nodes. The repository contains several Bash scripts and a malicious Git hook (post-checkout) designed to be executed when the repository is mounted via a vulnerable gitRepo volume. The scripts demonstrate successful exploitation by writing system, user, and process information to files in /tmp, confirming code execution. The presence of a symlink to the .git directory suggests an attempt to ensure the malicious hook is recognized and executed. The repository is structured for research and testing purposes, with clear warnings in the README about its malicious nature. No network endpoints are present; all actions are local to the compromised node.
This repository documents and provides a proof-of-concept exploit for CVE-2024-10220, a critical vulnerability in Kubernetes 1.27.x related to the deprecated gitRepo volume type. The vulnerability allows arbitrary command execution on the host running kubelet by leveraging a malicious .hooks directory in a Git repository. The README.md contains a full Python exploit script that crafts and sends a malicious pod manifest to the kubelet API endpoint, triggering the vulnerability. The repository also includes deployment examples using Terraform and Ansible, demonstrating how the exploit can be automated in a CI/CD pipeline. The main exploit capability is remote code execution on the Kubernetes host. The repository contains no actual code files except for the exploit script embedded in the README. Key fingerprintable endpoints include the kubelet API URL, the malicious Git repository, and file paths used in the exploit. The repository is intended for educational and defensive purposes, with responsible disclosure and mitigation advice provided.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.