Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h7wq-jj8r-qm7p

Опубликовано: 17 нояб. 2024
Источник: github
Github: Прошло ревью
CVSS3: 7.7

Описание

Kubernetes Nil pointer dereference in KCM after v1 HPA patch request

A flaw was found in kube-controller-manager. This issue occurs when the initial application of a HPA config YAML lacking a .spec.behavior.scaleUp block causes a denial of service due to KCM pods going into restart churn.

Пакеты

Наименование

k8s.io/kubernetes

go
Затронутые версииВерсия исправления

< 1.27.0-alpha.1

1.27.0-alpha.1

EPSS

Процентиль: 34%
0.00136
Низкий

7.7 High

CVSS3

Дефекты

CWE-20
CWE-476

Связанные уязвимости

CVSS3: 7.7
redhat
около 2 лет назад

A flaw was found in kube-controller-manager. This issue occurs when the initial application of a HPA config YAML lacking a .spec.behavior.scaleUp block causes a denial of service due to KCM pods going into restart churn.

CVSS3: 7.7
nvd
около 1 года назад

A flaw was found in kube-controller-manager. This issue occurs when the initial application of a HPA config YAML lacking a .spec.behavior.scaleUp block causes a denial of service due to KCM pods going into restart churn.

suse-cvrf
больше 1 года назад

Security update for kubernetes1.23

suse-cvrf
почти 2 года назад

Security update for kubernetes1.23

suse-cvrf
почти 2 года назад

Security update for kubernetes1.23

EPSS

Процентиль: 34%
0.00136
Низкий

7.7 High

CVSS3

Дефекты

CWE-20
CWE-476