Back

HIGH

Kubernetes API Server JSON/YAML parsing vulnerable to resource exhaustion attack

Published Oct 17, 2019

Description

Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API server to consume excessive CPU or memory, potentially crashing and becoming unavailable. Prior to v1.14.0, default RBAC policy authorized anonymous users to submit requests that could trigger this vulnerability. Clusters upgraded from a version prior to v1.14.0 keep the more permissive policy by default for backwards compatibility.

Affected products

Remediation

Vendor solution

Exposure to requests from unauthenticated users can be mitigated by removing all write permissions from unauthenticated users, following instructions at https://github.com/kubernetes/kubernetes/issues/83253

Red Hat statement

For Red Hat OpenStack Platform, because kubernetes is not directly used in director-operator, the RHOSP Impact has been moved to Moderate.

Metrics

References (16)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner kubernetes
Published Oct 17, 2019
Updated Sep 16, 2024
Reserved Apr 17, 2019
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Sep 28, 2019
GHSA-PMQP-H87C-MR78