Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-55qj-gj3x-jq9r

Опубликовано: 24 апр. 2024
Источник: github
Github: Прошло ревью
CVSS3: 5.5

Описание

Denial of service in Kubernetes

The Kubernetes kubelet component in versions 1.1-1.16.12, 1.17.0-1.17.8 and 1.18.0-1.18.5 do not account for disk usage by a pod which writes to its own /etc/hosts file. The /etc/hosts file mounted in a pod by kubelet is not included by the kubelet eviction manager when calculating ephemeral storage usage by a pod. If a pod writes a large amount of data to the /etc/hosts file, it could fill the storage space of the node and cause the node to fail.

Пакеты

Наименование

k8s.io/kubernetes/pkg/kubelet

go
Затронутые версииВерсия исправления

>= 1.1.0, < 1.16.13

1.16.13

Наименование

k8s.io/kubernetes/pkg/kubelet

go
Затронутые версииВерсия исправления

>= 1.17.0, < 1.17.9

1.17.9

Наименование

k8s.io/kubernetes/pkg/kubelet

go
Затронутые версииВерсия исправления

>= 1.18.0, < 1.18.6

1.18.6

EPSS

Процентиль: 39%
0.00172
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 5 лет назад

The Kubernetes kubelet component in versions 1.1-1.16.12, 1.17.0-1.17.8 and 1.18.0-1.18.5 do not account for disk usage by a pod which writes to its own /etc/hosts file. The /etc/hosts file mounted in a pod by kubelet is not included by the kubelet eviction manager when calculating ephemeral storage usage by a pod. If a pod writes a large amount of data to the /etc/hosts file, it could fill the storage space of the node and cause the node to fail.

CVSS3: 5.5
redhat
почти 5 лет назад

The Kubernetes kubelet component in versions 1.1-1.16.12, 1.17.0-1.17.8 and 1.18.0-1.18.5 do not account for disk usage by a pod which writes to its own /etc/hosts file. The /etc/hosts file mounted in a pod by kubelet is not included by the kubelet eviction manager when calculating ephemeral storage usage by a pod. If a pod writes a large amount of data to the /etc/hosts file, it could fill the storage space of the node and cause the node to fail.

CVSS3: 5.5
nvd
почти 5 лет назад

The Kubernetes kubelet component in versions 1.1-1.16.12, 1.17.0-1.17.8 and 1.18.0-1.18.5 do not account for disk usage by a pod which writes to its own /etc/hosts file. The /etc/hosts file mounted in a pod by kubelet is not included by the kubelet eviction manager when calculating ephemeral storage usage by a pod. If a pod writes a large amount of data to the /etc/hosts file, it could fill the storage space of the node and cause the node to fail.

CVSS3: 5.5
debian
почти 5 лет назад

The Kubernetes kubelet component in versions 1.1-1.16.12, 1.17.0-1.17. ...

suse-cvrf
почти 5 лет назад

Bugfixes on cilium, gangway and skuba and security fix for Kubernetes (cve-2020-8557)

EPSS

Процентиль: 39%
0.00172
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-400