Input validation error in Mesos - CVE-2018-1330
Published: September 13, 2018 / Updated: August 8, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
When parsing a malformed JSON payload, libprocess in Apache Mesos versions 1.4.0 to 1.5.0 might crash due to an uncaught exception. Parsing chunked HTTP requests with trailers can lead to a libprocess crash too because of the mistakenly planted assertion. A malicious actor can therefore cause a denial of service of Mesos masters rendering the Mesos-controlled cluster inoperable.
Affected software
Netcool Operations Insight
IBM Cloud Pak for Watson AIOps
How to mitigate CVE-2018-1330
Netcool Operations Insight - update to 1.6.8
IBM Cloud Pak for Watson AIOps - update to 3.7.1