Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jgfp-53c3-624w

Опубликовано: 13 фев. 2025
Источник: github
Github: Прошло ревью
CVSS3: 6.2

Описание

Node Denial of Service via kubelet Checkpoint API

A security issue was discovered in Kubernetes where a large number of container checkpoint requests made to the unauthenticated kubelet read-only HTTP endpoint may cause a Node Denial of Service by filling the Node's disk.

Пакеты

Наименование

k8s.io/kubernetes

go
Затронутые версииВерсия исправления

>= 1.32.0, < 1.32.2

1.32.2

Наименование

k8s.io/kubernetes

go
Затронутые версииВерсия исправления

>= 1.31.0, < 1.31.6

1.31.6

Наименование

k8s.io/kubernetes

go
Затронутые версииВерсия исправления

>= 1.30.0, < 1.30.10

1.30.10

Наименование

k8s.io/kubernetes

go
Затронутые версииВерсия исправления

< 1.29.14

1.29.14

EPSS

Процентиль: 6%
0.00027
Низкий

6.2 Medium

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 6.2
ubuntu
4 месяца назад

A security issue was discovered in Kubernetes where a large number of container checkpoint requests made to the unauthenticated kubelet read-only HTTP endpoint may cause a Node Denial of Service by filling the Node's disk.

CVSS3: 6.2
redhat
4 месяца назад

A security issue was discovered in Kubernetes where a large number of container checkpoint requests made to the unauthenticated kubelet read-only HTTP endpoint may cause a Node Denial of Service by filling the Node's disk.

CVSS3: 6.2
nvd
4 месяца назад

A security issue was discovered in Kubernetes where a large number of container checkpoint requests made to the unauthenticated kubelet read-only HTTP endpoint may cause a Node Denial of Service by filling the Node's disk.

CVSS3: 6.2
msrc
3 месяца назад

Описание отсутствует

CVSS3: 6.2
debian
4 месяца назад

A security issue was discovered in Kubernetes where a large number of ...

EPSS

Процентиль: 6%
0.00027
Низкий

6.2 Medium

CVSS3

Дефекты

CWE-400