You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API server to consume excessive CPU or memory, potentially crashing and becoming unavailable. Prior to v1.14.0, default RBAC policy authorized anonymous users to submit requests that could trigger this vulnerability. Clusters upgraded from a version prior to v1.14.0 keep the more permissive policy by default for backwards compatibility.
✔️ This issue was automatically closed by WhiteSource because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the WhiteSource inventory.
mend-bolt-for-githubbot
changed the title
CVE-2019-11253 (High) detected in github.com/containerd/containerd-v1.3.0
CVE-2019-11253 (High) detected in github.com/containerd/containerd-v1.3.0 - autoclosed
Oct 5, 2021
CVE-2019-11253 - High Severity Vulnerability
Vulnerable Library - github.com/containerd/containerd-v1.3.0
An open and reliable container runtime
Dependency Hierarchy:
Found in HEAD commit: d388e16464e00b9ce84df0d247029f534a429b90
Found in base branch: main
Vulnerability Details
Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API server to consume excessive CPU or memory, potentially crashing and becoming unavailable. Prior to v1.14.0, default RBAC policy authorized anonymous users to submit requests that could trigger this vulnerability. Clusters upgraded from a version prior to v1.14.0 keep the more permissive policy by default for backwards compatibility.
Publish Date: 2019-10-17
URL: CVE-2019-11253
CVSS 3 Score Details (7.5)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: kubernetes/kubernetes#83253
Release Date: 2019-10-17
Fix Resolution: v1.13.12;v1.14.8;v1.15.5;v1.16.2
Step up your Open Source Security Game with WhiteSource here
The text was updated successfully, but these errors were encountered: