Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qhm4-jxv7-j9pq

Опубликовано: 15 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Allocation of Resources Without Limits or Throttling and Uncontrolled Memory Allocation in Kubernetes

The Kubelet component in versions 1.15.0-1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via the kubelet API, including the unauthenticated HTTP read-only API typically served on port 10255, and the authenticated HTTPS API typically served on port 10250.

Пакеты

Наименование

k8s.io/kubernetes

go
Затронутые версииВерсия исправления

>= 1.15.0, < 1.15.10

1.15.10

Наименование

k8s.io/kubernetes

go
Затронутые версииВерсия исправления

>= 1.16.0, < 1.16.6

1.16.6

Наименование

k8s.io/kubernetes

go
Затронутые версииВерсия исправления

>= 1.17.0, < 1.17.2

1.17.2

EPSS

Процентиль: 52%
0.00295
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-770
CWE-789

Связанные уязвимости

CVSS3: 4.3
ubuntu
около 5 лет назад

The Kubelet component in versions 1.15.0-1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via the kubelet API, including the unauthenticated HTTP read-only API typically served on port 10255, and the authenticated HTTPS API typically served on port 10250.

CVSS3: 4.3
redhat
около 5 лет назад

The Kubelet component in versions 1.15.0-1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via the kubelet API, including the unauthenticated HTTP read-only API typically served on port 10255, and the authenticated HTTPS API typically served on port 10250.

CVSS3: 4.3
nvd
около 5 лет назад

The Kubelet component in versions 1.15.0-1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via the kubelet API, including the unauthenticated HTTP read-only API typically served on port 10255, and the authenticated HTTPS API typically served on port 10250.

CVSS3: 4.3
debian
около 5 лет назад

The Kubelet component in versions 1.15.0-1.15.9, 1.16.0-1.16.6, and 1. ...

EPSS

Процентиль: 52%
0.00295
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-770
CWE-789