Back

MEDIUM

Kubernetes API Server denial of service vulnerability from malicious YAML payloads

Published Apr 1, 2020

Description

The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an authorized user who sends malicious YAML payloads to cause the kube-apiserver to consume excessive CPU cycles while parsing YAML.

Affected products

Remediation

Red Hat statement

The upstream Kubernetes fix for this vulnerability is to update the version of the Go dependency, gopkg.in/yaml.v2. This issue affects OpenShift Container Platform components that use versions before 2.2.8 of gopkg.in/yaml.v2 and accept YAML payloads.

Red Hat mitigation

Prevent unauthenticated or unauthorized access to the API server

Metrics

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner kubernetes
Published Apr 1, 2020
Updated Sep 16, 2024
Reserved Apr 17, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Mar 27, 2020
GHSA-WXC4-F4M6-WWQV