Skip to content
Server & Web Software

Kubernetes SIG UI Kubernetes Dashboard — Default Password

Default username and password for the Kubernetes SIG UI Kubernetes Dashboard: (blank) / (blank). Learn how to log in and how to change the default credentials.

Kubernetes Dashboard v1.7.0 through v1.10.0 shipped with a 'Skip' login button enabled by default (CVE-2018-18264, CVSS 7.5). Clicking Skip bypassed authentication and granted the Dashboard service account's permissions — in many deployments this account had cluster-admin rights. Pre-v1.7 Dashboard had no login screen at all. Fixed in v1.10.1. Exploited in the 2018 Tesla cryptojacking incident where attackers accessed AWS credentials via an unauthenticated Dashboard exposed to the internet.

UsuarioContraseñaAccesoVersión / firmwareNotas
(vacío / ninguno)
(vacío / ninguno)
Web UI≤1.10.0Login bypass via 'Skip' button (CVE-2018-18264); pre-v1.7 had no login screen. Fixed in v1.10.1.

Uso responsable

Esta base de datos enumera credenciales predeterminadas documentadas públicamente para que los administradores puedan encontrarlas y cambiarlas. Úsalas solo en sistemas que poseas o que estés autorizado a probar.

Dispositivos relacionados