Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-1944: GitHub - kubernetes/minikube: Run Kubernetes locally

This vulnerability enables ssh access to minikube container using a default password.

CVE
#vulnerability#web#mac#windows#linux#git#kubernetes#ssh

minikube

minikube implements a local Kubernetes cluster on macOS, Linux, and Windows. minikube’s primary goals are to be the best tool for local Kubernetes application development and to support all Kubernetes features that fit.

Features

minikube runs the latest stable release of Kubernetes, with support for standard Kubernetes features like:

  • LoadBalancer - using minikube tunnel
  • Multi-cluster - using minikube start -p <name>
  • NodePorts - using minikube service
  • Persistent Volumes
  • Ingress
  • Dashboard - minikube dashboard
  • Container runtimes - minikube start --container-runtime
  • Configure apiserver and kubelet options via command-line flags
  • Supports common CI environments

As well as developer-friendly features:

  • Addons - a marketplace for developers to share configurations for running services on minikube
  • NVIDIA GPU support - for machine learning
  • Filesystem mounts

For more information, see the official minikube website

Installation

See the Getting Started Guide

📣 Please fill out our fast 5-question survey so that we can learn how & why you use minikube, and what improvements we should make. Thank you! 👯

Documentation

See https://minikube.sigs.k8s.io/docs/

More Examples

See minikube in action here

Community

minikube is a Kubernetes #sig-cluster-lifecycle project.

  • #minikube on Kubernetes Slack - Live chat with minikube developers!

  • minikube-users mailing list

  • minikube-dev mailing list

  • Contributing

  • Development Roadmap

Join our meetings:

  • Bi-weekly office hours, Mondays @ 11am PST
  • Triage Party

Related news

CVE-2023-1174: [Security Advisory] CVE-2023-1174, CVE-2023-1944: Network port exposure and ssh access using default password

This vulnerability exposes a network port in minikube running on macOS with Docker driver that could enable unexpected remote access to the minikube container.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907