MEDIUM6.5
GHSA-q4rr-64r9-fwgf
Kubernetes DoS Vulnerability
Quick fix
GHSA-q4rr-64r9-fwgf — k8s.io/kubernetes: upgrade to the fixed version with the command below.
go get k8s.io/kubernetes@v1.11.8Details
In all Kubernetes versions prior to v1.11.8, v1.12.6, and v1.13.4, users that are authorized to make patch requests to the Kubernetes API Server can send a specially crafted patch of type "json-patch" (e.g. `kubectl patch --type json` or `"Content-Type: application/json-patch+json"`) that consumes excessive resources while processing, causing a Denial of Service on the API Server.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/k8s.io/kubernetes
Introduced in:
1.0.0No fixed version published yet for k8s.io/kubernetes (go modules). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2019-1002100[ADVISORY]
- https://github.com/kubernetes/kubernetes/issues/74534[WEB]
- https://access.redhat.com/errata/RHSA-2019:1851[WEB]
- https://access.redhat.com/errata/RHSA-2019:3239[WEB]
- https://github.com/kubernetes/kubernetes[PACKAGE]
- https://groups.google.com/forum/#!topic/kubernetes-announce/vmUUNkYfG9g[WEB]
- https://security.netapp.com/advisory/ntap-20190416-0002[WEB]
- https://web.archive.org/web/20210125011246/https://www.securityfocus.com/bid/107290[WEB]