HIGH
mesos: stack overflow vulnerability in parser
Published Mar 5, 2019
7.5
HIGHCVSS 3.0
EPSS 4.97%
Description
When parsing a JSON payload with deeply nested JSON structures, the parser in Apache Mesos versions pre-1.4.x, 1.4.0 to 1.4.2, 1.5.0 to 1.5.1, 1.6.0 to 1.6.1, and 1.7.0 might overflow the stack due to unbounded recursion. A malicious actor can therefore cause a denial of service of Mesos masters rendering the Mesos-controlled cluster inoperable.
Affected products
-
Affected
- Apache Mesos pre-1.4.x, 1.4.0 to 1.4.2, 1.5.0 to 1.5.1, 1.6.0 to 1.6.1, 1.7.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Apache Software Foundation | Apache Mesos | unknown | Affected
|
OR
- ≥ 1.4.0 · < 1.4.3
- ≥ 1.5.0 · < 1.5.2
- ≥ 1.6.0 · < 1.6.2
- ≥ 1.7.0 · < 1.7.1
- 1.4.0
- 1.4.0
- 1.4.0
- 1.4.0
- 1.4.0
- 1.8.0
No data.
Red Hat Fuse 7
mesos
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Fuse 7 | mesos | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (9)
- http://www.securityfocus.com/bid/107281 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2018-11793 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1687364 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-0387 Advisory
- https://github.com/advisories/GHSA-p2xq-vcm7-xjj6 Advisory
- https://lists.apache.org/thread.html/9be975c53e5ad612c7e0af39f5b88837fbfbc32108e587d3d8499844%40%3Cdev.mesos.apache.org%3E x_refsource_MISC
- https://lists.apache.org/thread.html/9be975c53e5ad612c7e0af39f5b88837fbfbc32108e587d3d8499844@%3Cdev.mesos.apache.org%3E
- https://nvd.nist.gov/vuln/detail/CVE-2018-11793
- https://www.cve.org/CVERecord?id=CVE-2018-11793
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Mar 5, 2019
Updated Sep 16, 2024
Reserved Jun 5, 2018
Link CVE-2018-11793
CISA Vulnrichment
No data
GitHub
Link GHSA-P2XQ-VCM7-XJJ6