← Back

CVE-2018-1330

nvd nist
Published: Sep 13, 2018Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

When parsing a malformed JSON payload, libprocess in Apache Mesos versions 1.4.0 to 1.5.0 might crash due to an uncaught exception. Parsing chunked HTTP requests with trailers can lead to a libprocess crash too because of the mistakenly planted assertion. A malicious actor can therefore cause a denial of service of Mesos masters rendering the Mesos-controlled cluster inoperable.

Affected (8)

Products: Apache: Mesos
1 product
Mesos
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Apache
From 1.4.0 to 1.4.2
From 1.5.0 to 1.5.1
Version 1.4.0 rc1
Version 1.4.0 rc2
Version 1.4.0 rc3
Version 1.4.0 rc4
Version 1.4.0 rc5
Version 1.6.0 rc1

Timeline

No history available yet.