Resource exhaustion in Kubernetes - CVE-2019-11254

 

Resource exhaustion in Kubernetes - CVE-2019-11254

Published: April 1, 2020 / Updated: July 17, 2020


Vulnerability identifier: #VU30318
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-11254
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to perform a denial of service (DoS) attack.

The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an authorized user who sends malicious YAML payloads to cause the kube-apiserver to consume excessive CPU cycles while parsing YAML.


Affected software

Kubernetes
Red Hat OpenShift Container Platform
IBM Watson Machine Learning Accelerator
IBM Cloud Pak for Watson AIOps
Robotic Process Automation for Cloud Pak
IBM Fusion HCI
atomic-openshift (Red Hat package)
openshift (Red Hat package)
machine-config-daemon (Red Hat package)
IBM CICS TX Advanced
IBM CICS TX Standard

How to mitigate CVE-2019-11254

Install update from vendor's website.

Kubernetes - update to 1.17.3
IBM Watson Machine Learning Accelerator - update to 2.3.9
IBM Fusion HCI - update to 2.6.1
atomic-openshift (Red Hat package) - update to 3.11.232-1.git.0.a5bc32f.el7
IBM Cloud Pak for Watson AIOps - update to 4.1
openshift (Red Hat package) - addressed in versions 4.5.0-202007012112.p0.git.0.582d7fc.el7, 4.5.0-202007012112.p0.git.0.582d7fc.el8
machine-config-daemon (Red Hat package) - update to 4.5.0-202007012112.p0.git.2527.d12c3da.el8
IBM CICS TX Advanced - update to 11.1.0.0 ifix5
IBM CICS TX Standard - update to 11.1.0.0 ifix5
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.10, 23.0.10

External References

Related Security Bulletins