Описание
The Kubernetes API server component in versions prior to 1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via successful API requests.
A denial of service vulnerability was found in the Kubernetes API server. This flaw allows a remote attacker to send repeated, crafted HTTP requests to exhaust available memory and cause a crash.
Меры по смягчению последствий
Prevent unauthenticated or unauthorized access to all APIs
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat OpenShift Container Platform 4 | openshift4/ose-hypershift | Will not fix | ||
Red Hat OpenShift Container Platform 4 | openshift4/ose-service-catalog | Will not fix | ||
Red Hat Storage 3 | heketi | Not affected | ||
Red Hat OpenShift Container Platform 3.11 | atomic-enterprise-service-catalog | Fixed | RHBA-2020:2215 | 28.05.2020 |
Red Hat OpenShift Container Platform 3.11 | atomic-openshift | Fixed | RHBA-2020:2215 | 28.05.2020 |
Red Hat OpenShift Container Platform 3.11 | atomic-openshift-cluster-autoscaler | Fixed | RHBA-2020:2215 | 28.05.2020 |
Red Hat OpenShift Container Platform 3.11 | atomic-openshift-descheduler | Fixed | RHBA-2020:2215 | 28.05.2020 |
Red Hat OpenShift Container Platform 3.11 | atomic-openshift-dockerregistry | Fixed | RHBA-2020:2215 | 28.05.2020 |
Red Hat OpenShift Container Platform 3.11 | atomic-openshift-metrics-server | Fixed | RHBA-2020:2215 | 28.05.2020 |
Red Hat OpenShift Container Platform 3.11 | atomic-openshift-node-problem-detector | Fixed | RHBA-2020:2215 | 28.05.2020 |
Показывать по
Дополнительная информация
Статус:
EPSS
4.3 Medium
CVSS3
Связанные уязвимости
The Kubernetes API server component in versions prior to 1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via successful API requests.
The Kubernetes API server component in versions prior to 1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via successful API requests.
The Kubernetes API server component in versions prior to 1.15.9, 1.16. ...
EPSS
4.3 Medium
CVSS3