Kubernetes DoS Vulnerability
Moderate severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Sep 28, 2023
Package
Affected versions
>= 1.0, <= 1.10
>= 1.11.0, <= 1.11.7
>= 1.12.0, <= 1.12.5
>= 1.13.0, <= 1.13.3
Patched versions
1.11.8
1.12.6
1.13.4
Description
Published by the National Vulnerability Database
Apr 1, 2019
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Jul 19, 2023
Last updated
Sep 28, 2023
In all Kubernetes versions prior to v1.11.8, v1.12.6, and v1.13.4, users that are authorized to make patch requests to the Kubernetes API Server can send a specially crafted patch of type "json-patch" (e.g.
kubectl patch --type json
or"Content-Type: application/json-patch+json"
) that consumes excessive resources while processing, causing a Denial of Service on the API Server.References