Back

HIGH

mesos: stack overflow vulnerability in parser

Published Mar 5, 2019

Description

When parsing a JSON payload with deeply nested JSON structures, the parser in Apache Mesos versions pre-1.4.x, 1.4.0 to 1.4.2, 1.5.0 to 1.5.1, 1.6.0 to 1.6.1, and 1.7.0 might overflow the stack due to unbounded recursion. A malicious actor can therefore cause a denial of service of Mesos masters rendering the Mesos-controlled cluster inoperable.

Affected products

Remediation

No remediation recorded yet.

References (9)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner apache
Published Mar 5, 2019
Updated Sep 16, 2024
Reserved Jun 5, 2018

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Mar 4, 2019
Bugzilla 1687364

ENISA EUVD

Assigner apache
Published Mar 5, 2019
Updated Sep 16, 2024