Resource exhaustion in Kubernetes - CVE-2019-11254
Published: April 1, 2020 / Updated: July 17, 2020
Vulnerability details
The vulnerability allows a remote authenticated user to perform a denial of service (DoS) attack.
The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an authorized user who sends malicious YAML payloads to cause the kube-apiserver to consume excessive CPU cycles while parsing YAML.
Affected software
Red Hat OpenShift Container Platform
IBM Watson Machine Learning Accelerator
IBM Cloud Pak for Watson AIOps
Robotic Process Automation for Cloud Pak
IBM Fusion HCI
atomic-openshift (Red Hat package)
openshift (Red Hat package)
machine-config-daemon (Red Hat package)
IBM CICS TX Advanced
IBM CICS TX Standard
How to mitigate CVE-2019-11254
IBM Watson Machine Learning Accelerator - update to 2.3.9
IBM Fusion HCI - update to 2.6.1
atomic-openshift (Red Hat package) - update to 3.11.232-1.git.0.a5bc32f.el7
IBM Cloud Pak for Watson AIOps - update to 4.1
openshift (Red Hat package) - addressed in versions 4.5.0-202007012112.p0.git.0.582d7fc.el7, 4.5.0-202007012112.p0.git.0.582d7fc.el8
machine-config-daemon (Red Hat package) - update to 4.5.0-202007012112.p0.git.2527.d12c3da.el8
IBM CICS TX Advanced - update to 11.1.0.0 ifix5
IBM CICS TX Standard - update to 11.1.0.0 ifix5
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.10, 23.0.10
External References
Related Security Bulletins
- Resource exhaustion in Kubernetes Kubernetes
- Red Hat OpenShift Container Platform 3.11 update for atomic-openshift
- Multiple vulnerabilities in IBM CICS TX Advanced
- Multiple vulnerabilities in IBM CICS TX Standard
- Multiple vulnerabilities in IBM Storage Fusion and IBM Storage Fusion HCI
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Multiple vulnerabilities in IBM Watson Machine Learning Accelerator on Cloud Pak for Data
- Red Hat OpenShift Container Platform 4 update for machine-config-daemon and openshift