Resource exhaustion in Kubernetes - CVE-2019-11253

 

Resource exhaustion in Kubernetes - CVE-2019-11253

Published: November 18, 2019


Vulnerability identifier: #VU22824
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-11253
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation when processing YAML or JSON data in Kubernetes API server. A remote attacker can pass a malicious file to the API server and consume excessive memory and CPU resources, leading to a denial of service (DoS) attack.

Note, this vulnerability can be exploited by a remote non-authenticated attacker in Kubernetes versions prior to 1.14.0 due to default RBAC policy.


Affected software

Kubernetes
containerd (Alpine package)
servicemesh-cni (Red Hat package)
servicemesh-prometheus (Red Hat package)
atomic-openshift (Red Hat package)
openshift (Red Hat package)
servicemesh-grafana (Red Hat package)
Red Hat OpenShift Container Platform
Netcool Operations Insight
IBM Maximo Application Suite
Red Hat OpenStack
IBM Cloud Pak for Watson AIOps
IBM CICS TX Advanced
IBM CICS TX Standard

How to mitigate CVE-2019-11253

Install updates from vendor's website.

Kubernetes - addressed in versions 1.13.12, 1.14.8, 1.15.5, 1.16.2
containerd (Alpine package) - update to 1.3.3-r0
servicemesh-cni (Red Hat package) - addressed in versions 1.0.11-1.el8, 1.1.4-2.el8
Netcool Operations Insight - update to 1.6.12
servicemesh-prometheus (Red Hat package) - update to 2.7.2-36.el8
atomic-openshift (Red Hat package) - update to 3.10.181-1.git.0.3ab4b3d.el7
openshift (Red Hat package) - addressed in versions 4.1.20-201910101746.git.0.a80aad5.el7, 4.1.20-201910101746.git.0.a80aad5.el8
IBM Cloud Pak for Watson AIOps - update to 4.8.1
servicemesh-grafana (Red Hat package) - update to 6.2.2-38.el8
IBM Maximo Application Suite - addressed in versions 8.10.16, 8.11.14, 9.0.1
IBM CICS TX Advanced - update to 11.1.0.0 ifix5
IBM CICS TX Standard - update to 11.1.0.0 ifix5
Red Hat OpenStack - update to 16.2

External References

Related Security Bulletins