SCA: security update for github.com/openkruise/kruise (GHSA-9fj4-3849-rv9g)

high Tenable Self-Hosted Container Security Plugin ID 438048

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Kruise provides automated management of large-scale applications on Kubernetes. Prior to versions 1.8.3
and 1.7.5, PodProbeMarker allows defining custom probes with TCPSocket or HTTPGet handlers. The webhook
validation does not restrict the Host field in these probe configurations. Since kruise-daemon runs with
hostNetwork=true, it executes probes from the node network namespace. An attacker with PodProbeMarker
creation permission can specify arbitrary Host values to trigger SSRF from the node, perform port
scanning, and receive response feedback through NodePodProbe status messages. Versions 1.8.3 and 1.7.5
patch the issue. (CVE-2026-24005)

See Also

https://github.com/advisories/GHSA-9fj4-3849-rv9g

Plugin Details

Severity: High

ID: 438048

Version: Revision 1.4

Type: Local

Family: SCA Checks

Published: 3/2/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3.9

Percentile: 52.77

Vendor

Vendor Severity: Low

CVSS v2

Risk Factor: High

Base Score: 8

Temporal Score: 6.3

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:P/A:P

CVSS Score Source: CVE-2026-24005

CVSS v3

Risk Factor: High

Base Score: 7.6

Temporal Score: 6.8

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2/25/2026

Vulnerability Publication Date: 2/25/2026

Reference Information

CVE: CVE-2026-24005

cwe: CWE-918