← Back

CVE-2019-1002100

nvd nist
Published: Apr 1, 2019Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

In all Kubernetes versions prior to v1.11.8, v1.12.6, and v1.13.4, users that are authorized to make patch requests to the Kubernetes API Server can send a specially crafted patch of type "json-patch" (e.g. `kubectl patch --type json` or `"Content-Type: application/json-patch+json"`) that consumes excessive resources while processing, causing a Denial of Service on the API Server.

Affected (5)

1 product
Kubernetes
1 product
Openshift Container Platform
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Kubernetes
Before 1.11.8
From 1.12.0 to 1.12.6
From 1.13.0 to 1.13.4
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 3.10
Version 3.11

References (12)

Source: josh@bress.net
Broken LinkThird Party AdvisoryVDB Entry
Source: josh@bress.net
Third Party Advisory
Source: josh@bress.net
Third Party Advisory
Source: josh@bress.net
Issue TrackingVendor Advisory
Source: josh@bress.net
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.