PT-2019-5264 · Kubernetes+1 · Kubernetes+1

CVE-2019-1002100

·

Publicado

2019-02-28

·

Atualizado

2025-08-08

CVSS v2.0

6.8

Média

VetorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Kubernetes versions prior to 1.11.8 Kubernetes versions prior to 1.12.6 Kubernetes versions prior to 1.13.4
Description The issue is related to an uncontrolled resource consumption in the Kubernetes API Server. It can be exploited by sending a specially crafted patch of type "json-patch" (e.g., kubectl patch --type json or "Content-Type: application/json-patch+json") that consumes excessive resources while processing, causing a Denial of Service on the API Server. This can be done by users authorized to make patch requests to the Kubernetes API Server.
Recommendations For versions prior to 1.11.8, update to version 1.11.8 or later. For versions prior to 1.12.6, update to version 1.12.6 or later. For versions prior to 1.13.4, update to version 1.13.4 or later.

Correção

DoS

Resource Exhaustion

Allocation of Resources Without Limits

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-1504
BDU:2020-02155
CVE-2019-1002100
GHSA-Q4RR-64R9-FWGF
GO-2023-1946
OPENSUSE-SU-2025:15424-1
RHSA-2019:1851
RHSA-2019:3239

Produtos afetados

Alt Linux
Kubernetes