PT-2019-5264 · Kubernetes+1 · Kubernetes+1

Published

2019-02-28

·

Updated

2025-08-08

·

CVE-2019-1002100

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Kubernetes versions prior to 1.11.8 Kubernetes versions prior to 1.12.6 Kubernetes versions prior to 1.13.4
Description The issue is related to an uncontrolled resource consumption in the Kubernetes API Server. It can be exploited by sending a specially crafted patch of type "json-patch" (e.g., kubectl patch --type json or "Content-Type: application/json-patch+json") that consumes excessive resources while processing, causing a Denial of Service on the API Server. This can be done by users authorized to make patch requests to the Kubernetes API Server.
Recommendations For versions prior to 1.11.8, update to version 1.11.8 or later. For versions prior to 1.12.6, update to version 1.12.6 or later. For versions prior to 1.13.4, update to version 1.13.4 or later.

Fix

DoS

Allocation of Resources Without Limits

Resource Exhaustion

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1504
BDU:2020-02155
CVE-2019-1002100
GHSA-Q4RR-64R9-FWGF
GO-2023-1946
OPENSUSE-SU-2025:15424-1
RHSA-2019:1851
RHSA-2019:3239

Affected Products

Alt Linux
Kubernetes