PT-2023-7334 · Unknown · Knative Serving

Adamkorcz

·

Published

2023-10-16

·

Updated

2024-08-21

·

CVE-2023-48713

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Knative Serving versions prior to 0.39.0 Knative Serving versions prior to v1.10.5 Knative Serving versions prior to v1.11.3 Knative Serving versions prior to v1.12.0
Description The issue is related to an unbound memory allocation bug in Knative Serving, which can cause a Denial-of-Service (DoS) of the autoscaler. An attacker who controls a pod and can control the responses from the "/metrics" endpoint can exploit this bug. This vulnerability allows a non-privileged Knative user to cause a DoS for the cluster. The root cause is a memory exhaustion issue in the autoscaler that can be triggered by a malicious response.
Recommendations For versions prior to 0.39.0, update to version 0.39.0 or later. For versions prior to v1.10.5, update to version v1.10.5 or later. For versions prior to v1.11.3, update to version v1.11.3 or later. For versions prior to v1.12.0, update to version v1.12.0 or later. As a temporary workaround, consider restricting access to the "/metrics" endpoint to minimize the risk of exploitation.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-08365
CVE-2023-48713
GHSA-QMVJ-4QR9-V547
GO-2023-2355

Affected Products

Knative Serving