VDB
Sign up
MEDIUM6.5

GHSA-q4rr-64r9-fwgf

Kubernetes DoS Vulnerability

Quick fix

GHSA-q4rr-64r9-fwgf — k8s.io/kubernetes: upgrade to the fixed version with the command below.

go get k8s.io/kubernetes@v1.11.8

Details

In all Kubernetes versions prior to v1.11.8, v1.12.6, and v1.13.4, users that are authorized to make patch requests to the Kubernetes API Server can send a specially crafted patch of type "json-patch" (e.g. `kubectl patch --type json` or `"Content-Type: application/json-patch+json"`) that consumes excessive resources while processing, causing a Denial of Service on the API Server.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/k8s.io/kubernetes
Introduced in: 1.0.0

No fixed version published yet for k8s.io/kubernetes (go modules). Pin to a known-safe version or switch to an alternative.

Go/k8s.io/kubernetes
Introduced in: 1.11.0Fixed in: 1.11.8
Fixgo get k8s.io/kubernetes@v1.11.8
Go/k8s.io/kubernetes
Introduced in: 1.12.0Fixed in: 1.12.6
Fixgo get k8s.io/kubernetes@v1.12.6
Go/k8s.io/kubernetes
Introduced in: 1.13.0Fixed in: 1.13.4
Fixgo get k8s.io/kubernetes@v1.13.4

References