Resource exhaustion in Kubernetes - CVE-2019-11253
Published: November 18, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation when processing YAML or JSON data in Kubernetes API server. A remote attacker can pass a malicious file to the API server and consume excessive memory and CPU resources, leading to a denial of service (DoS) attack.
Note, this vulnerability can be exploited by a remote non-authenticated attacker in Kubernetes versions prior to 1.14.0 due to default RBAC policy.
Affected software
containerd (Alpine package)
servicemesh-cni (Red Hat package)
servicemesh-prometheus (Red Hat package)
atomic-openshift (Red Hat package)
openshift (Red Hat package)
servicemesh-grafana (Red Hat package)
Red Hat OpenShift Container Platform
Netcool Operations Insight
IBM Maximo Application Suite
Red Hat OpenStack
IBM Cloud Pak for Watson AIOps
IBM CICS TX Advanced
IBM CICS TX Standard
How to mitigate CVE-2019-11253
containerd (Alpine package) - update to 1.3.3-r0
servicemesh-cni (Red Hat package) - addressed in versions 1.0.11-1.el8, 1.1.4-2.el8
Netcool Operations Insight - update to 1.6.12
servicemesh-prometheus (Red Hat package) - update to 2.7.2-36.el8
atomic-openshift (Red Hat package) - update to 3.10.181-1.git.0.3ab4b3d.el7
openshift (Red Hat package) - addressed in versions 4.1.20-201910101746.git.0.a80aad5.el7, 4.1.20-201910101746.git.0.a80aad5.el8
IBM Cloud Pak for Watson AIOps - update to 4.8.1
servicemesh-grafana (Red Hat package) - update to 6.2.2-38.el8
IBM Maximo Application Suite - addressed in versions 8.10.16, 8.11.14, 9.0.1
IBM CICS TX Advanced - update to 11.1.0.0 ifix5
IBM CICS TX Standard - update to 11.1.0.0 ifix5
Red Hat OpenStack - update to 16.2
External References
Related Security Bulletins
- Denial of service in Kubernetes API server
- Red Hat update for OpenShift Container Platform 3.11 atomic-openshift
- Resource exhaustion in containerd (Alpine package)
- Red Hat OpenShift Container Platform 4.1 update for openshift
- Red Hat OpenShift Container Platform 3.10 update for atomic-openshift
- OpenShift Service Mesh 1.1 update for servicemesh-cni
- OpenShift Service Mesh 1.0 update for servicemesh-prometheus
- OpenShift Service Mesh 1.0 update for servicemesh-cni
- Multiple vulnerabilities in IBM CICS TX Advanced
- Multiple vulnerabilities in IBM CICS TX Standard
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in IBM Maximo Application Suite
- Multiple vulnerabilities in Red Hat OpenStack 16.2 packages
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- OpenShift Service Mesh 1 update for servicemesh-grafana