VDB
Sign up
MEDIUM6.5

GHSA-wxc4-f4m6-wwqv

Excessive Platform Resource Consumption within a Loop in Kubernetes

Quick fix

GHSA-wxc4-f4m6-wwqv — gopkg.in/yaml.v2: upgrade to the fixed version with the command below.

go get gopkg.in/yaml.v2@v2.2.8

Details

The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an authorized user who sends malicious YAML payloads to cause the kube-apiserver to consume excessive CPU cycles while parsing YAML.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/gopkg.in/yaml.v2
Introduced in: 0Fixed in: 2.2.8
Fixgo get gopkg.in/yaml.v2@v2.2.8
Go/github.com/go-yaml/yaml
Introduced in: 0

No fixed version published yet for github.com/go-yaml/yaml (go modules). Pin to a known-safe version or switch to an alternative.

References