CVE-2019-11253

Scores

EPSS

0.838high83.8%
0%20%40%60%80%100%

Percentile: 83.8%

CVSS

7.5high3.x
0246810

CVSS Score: 7.5/10

All CVSS Scores

CVSS 3.x
7.5

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS 2.0
5.0

Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Description

Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API server to consume excessive CPU or memory, potentially crashing and becoming unavailable. Prior to v1.14.0, default RBAC policy authorized anonymous users to submit requests that could trigger this vulnerability. Clusters upgraded from a version prior to v1.14.0 keep the more permissive policy by default for backwards compatibility.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

debiannvdredhatubuntu

CWEs

CWE-20CWE-400CWE-776

Related Vulnerabilities

Recommendations

Source: nvd

For OpenShift Container Platform 3.11, see the following documentation, whichwill be updated shortly for release 3.11.154, for important instructions onhow to upgrade your cluster and fully apply this asynchronous errataupdate:
https://docs.openshift.com/container-platform/3.11/release_notes/ocp_3_11_release_notes.html

URL: https://access.redhat.com/errata/RHSA-2019:3905

Vulnerable Software (29)

Type: Configuration

Product: atomic-openshift

Operating System: rhel

Trait:
{  "fixed": "3.10.181-1.git.0.3ab4b3d.el7"}

Source: redhat

Type: Configuration

Product: atomic-openshift

Operating System: rhel

Trait:
{  "fixed": "3.11.154-1.git.0.7a097ad.el7"}

Source: redhat

Type: Configuration

Product: atomic-openshift

Operating System: rhel

Trait:
{  "fixed": "3.9.102-1.git.0.6411f52.el7"}

Source: redhat

Type: Configuration

Product: jaeger

Operating System: rhel

Trait:
{  "fixed": "1.13.1.redhat5-1.el7"}

Source: redhat

Type: Configuration

Product: jaeger-operator

Operating System: rhel

Trait:
{  "fixed": "1.13.1.redhat8-1.el7"}

Source: redhat

Type: Configuration

Product: kiali

Operating System: rhel

Trait:
{  "fixed": "1.0.7.redhat1-1.el7"}

Source: redhat

Type: Configuration

Product: kubernetes

Operating System: debian

Trait:
{  "fixed": "1.17.4-1"}

Source: debian

Type: Configuration

Product: kubernetes

Operating System: ubuntu disco 19.04

Trait:
{  "unfixed": true}

Source: ubuntu

Type: Configuration

Product: kubernetes-client

Operating System: altlinux

Trait:
{  "fixed": "0:1.16.4-alt1"}

Source: redhat

Type: Configuration

Product: kubernetes-common

Operating System: altlinux

Trait:
{  "fixed": "0:1.16.4-alt1"}

Source: redhat

Type: Configuration

Product: kubernetes-kubeadm

Operating System: altlinux

Trait:
{  "fixed": "0:1.16.4-alt1"}

Source: redhat

Type: Configuration

Product: kubernetes-kubelet

Operating System: altlinux

Trait:
{  "fixed": "0:1.16.4-alt1"}

Source: redhat

Type: Configuration

Product: kubernetes-master

Operating System: altlinux

Trait:
{  "fixed": "0:1.16.4-alt1"}

Source: redhat

Type: Configuration

Product: kubernetes-node

Operating System: altlinux

Trait:
{  "fixed": "0:1.16.4-alt1"}

Source: redhat

Type: Configuration

Product: openshift

Operating System: rhel

Trait:
{  "fixed": "4.1.20-201910101746.git.0.a80aad5.el8"}

Source: redhat

Type: Configuration

Product: servicemesh

Operating System: rhel

Trait:
{  "fixed": "1.0.2-3.el8"}

Source: redhat

Type: Configuration

Product: servicemesh-cni

Operating System: rhel

Trait:
{  "fixed": "1.0.2-3.el8"}

Source: redhat

Type: Configuration

Product: servicemesh-cni

Operating System: rhel

Trait:
{  "fixed": "1.0.11-1.el8"}

Source: redhat

Type: Configuration

Product: servicemesh-cni

Operating System: rhel

Trait:
{  "fixed": "1.1.4-2.el8"}

Source: redhat

Type: Configuration

Product: servicemesh-grafana

Operating System: rhel

Trait:
{  "fixed": "6.4.3-11.el8"}

Source: redhat