CVE-2019-1002100
published 2019-04-01CVE-2019-1002100: In all Kubernetes versions prior to v1.11.8, v1.12.6, and v1.13.4, users that are authorized to make patch requests to the Kubernetes API Server can send a…
PriorityP342medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
10.61%
95.3th percentile
In all Kubernetes versions prior to v1.11.8, v1.12.6, and v1.13.4, users that are authorized to make patch requests to the Kubernetes API Server can send a specially crafted patch of type "json-patch" (e.g. `kubectl patch --type json` or `"Content-Type: application/json-patch+json"`) that consumes excessive resources while processing, causing a Denial of Service on the API Server.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | kubernetes | < kubernetes 1.17.4-1 (bookworm) | kubernetes 1.17.4-1 (bookworm) |
| k8s.io | kubernetes | >= 1.0.0 < 1.11.8 | 1.11.8 |
| k8s.io | kubernetes | 1.0.0 – 1.10.14 | — |
| k8s.io | kubernetes | >= 1.11.0 < 1.11.8 | 1.11.8 |
| k8s.io | kubernetes | >= 1.12.0 < 1.12.6 | 1.12.6 |
| k8s.io | kubernetes | >= 1.13.0 < 1.13.4 | 1.13.4 |
| kubernetes | kubernetes | < 1.11.8 | 1.11.8 |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | >= 0 < 1.17.4-1 | 1.17.4-1 |
| kubernetes | kubernetes | >= 0 < 1.17.4-1 | 1.17.4-1 |
| kubernetes | kubernetes | >= 0 < 1.17.4-1 | 1.17.4-1 |
| kubernetes | kubernetes | >= 0 < 1.17.4-1 | 1.17.4-1 |
| kubernetes | kubernetes | >= 1.12.0 < 1.12.6 | 1.12.6 |
| kubernetes | kubernetes | >= 1.13.0 < 1.13.4 | 1.13.4 |
| kubernetes | kubernetes | >= unspecified < v1.11.8 | v1.11.8 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Kubernetes DoS Vulnerability in k8s.io/kubernetes
osv·2024-08-20
CVE-2019-1002100 Kubernetes DoS Vulnerability in k8s.io/kubernetes
Kubernetes DoS Vulnerability in k8s.io/kubernetes
Kubernetes DoS Vulnerability in k8s.io/kubernetes
GHSA
Kubernetes DoS Vulnerability
ghsa·2022-05-13
CVE-2019-1002100 [MEDIUM] CWE-770 Kubernetes DoS Vulnerability
Kubernetes DoS Vulnerability
In all Kubernetes versions prior to v1.11.8, v1.12.6, and v1.13.4, users that are authorized to make patch requests to the Kubernetes API Server can send a specially crafted patch of type "json-patch" (e.g. `kubectl patch --type json` or `"Content-Type: application/json-patch+json"`) that consumes excessive resources while processing, causing a Denial of Service on the API Server.
OSV
Kubernetes DoS Vulnerability
osv·2022-05-13
CVE-2019-1002100 [MEDIUM] Kubernetes DoS Vulnerability
Kubernetes DoS Vulnerability
In all Kubernetes versions prior to v1.11.8, v1.12.6, and v1.13.4, users that are authorized to make patch requests to the Kubernetes API Server can send a specially crafted patch of type "json-patch" (e.g. `kubectl patch --type json` or `"Content-Type: application/json-patch+json"`) that consumes excessive resources while processing, causing a Denial of Service on the API Server.
OSV
CVE-2019-1002100: In all Kubernetes versions prior to v1
osv·2019-04-01·CVSS 6.5
CVE-2019-1002100 [MEDIUM] CVE-2019-1002100: In all Kubernetes versions prior to v1
In all Kubernetes versions prior to v1.11.8, v1.12.6, and v1.13.4, users that are authorized to make patch requests to the Kubernetes API Server can send a specially crafted patch of type "json-patch" (e.g. `kubectl patch --type json` or `"Content-Type: application/json-patch+json"`) that consumes excessive resources while processing, causing a Denial of Service on the API Server.
Red Hat
kube-apiserver: DoS with crafted patch of type json-patch
vendor_redhat·2019-02-28·CVSS 6.5
CVE-2019-1002100 [MEDIUM] CWE-770 kube-apiserver: DoS with crafted patch of type json-patch
kube-apiserver: DoS with crafted patch of type json-patch
In all Kubernetes versions prior to v1.11.8, v1.12.6, and v1.13.4, users that are authorized to make patch requests to the Kubernetes API Server can send a specially crafted patch of type "json-patch" (e.g. `kubectl patch --type json` or `"Content-Type: application/json-patch+json"`) that consumes excessive resources while processing, causing a Denial of Service on the API Server.
A denial of service vulnerability was found in the Kubernetes API server. A remote user, with authorization to apply patches, could exploit this via crafted JSON input, causing excessive consumption of resources and subsequent denial of service.
Statement: This issue affects the Kubernetes API Server, shipped in OpenShift Container Platform versions 3.4
Debian
CVE-2019-1002100: kubernetes - In all Kubernetes versions prior to v1.11.8, v1.12.6, and v1.13.4, users that ar...
vendor_debian·2019·CVSS 6.5
CVE-2019-1002100 [MEDIUM] CVE-2019-1002100: kubernetes - In all Kubernetes versions prior to v1.11.8, v1.12.6, and v1.13.4, users that ar...
In all Kubernetes versions prior to v1.11.8, v1.12.6, and v1.13.4, users that are authorized to make patch requests to the Kubernetes API Server can send a specially crafted patch of type "json-patch" (e.g. `kubectl patch --type json` or `"Content-Type: application/json-patch+json"`) that consumes excessive resources while processing, causing a Denial of Service on the API Server.
Scope: local
bookworm: resolved (fixed in 1.17.4-1)
bullseye: resolved (fixed in 1.17.4-1)
forky: resolved (fixed in 1.17.4-1)
sid: resolved (fixed in 1.17.4-1)
trixie: resolved (fixed in 1.17.4-1)
No detection rules found.
No public exploits indexed.
Trendmicro
Analyzing How TeamTNT Used Compromised Docker Hub Accounts
blogs_trendmicro·2021-12-01
Analyzing How TeamTNT Used Compromised Docker Hub Accounts
Cloud
## Analyzing How TeamTNT Used Compromised Docker Hub Accounts
Following our previous disclosure of compromised Docker hub accounts delivering cryptocurrency miners, we analyze these accounts and discover more malicious actions that you need to be aware of.
By: Trend Micro Research Dec 01, 2021 Read time: ( words)
Save to Folio
In early November, we disclosed that compromised Docker Hub accounts were being used for cryptocurrency mining and that these activities were tied to the TeamTNT threat actor. While those accounts have now been removed, we were still able to investigate TeamTNT’s activities in connection with these compromised accounts.
In addition to the behavior we noted earlier, we identified several other actions that the same threat actor carried out in different ven
Trendmicro
Analyzing How TeamTNT Used Compromised Docker Hub Accounts
blogs_trendmicro·2021-12-01
Analyzing How TeamTNT Used Compromised Docker Hub Accounts
Nube
## Analyzing How TeamTNT Used Compromised Docker Hub Accounts
Following our previous disclosure of compromised Docker hub accounts delivering cryptocurrency miners, we analyze these accounts and discover more malicious actions that you need to be aware of.
By: Trend Micro Research Dec 01, 2021 Read time: ( words)
Save to Folio
In early November, we disclosed that compromised Docker Hub accounts were being used for cryptocurrency mining and that these activities were tied to the TeamTNT threat actor. While those accounts have now been removed, we were still able to investigate TeamTNT’s activities in connection with these compromised accounts.
In addition to the behavior we noted earlier, we identified several other actions that the same threat actor carried out in different venu
Trendmicro
Analyzing How TeamTNT Used Compromised Docker Hub Accounts
blogs_trendmicro·2021-12-01
Analyzing How TeamTNT Used Compromised Docker Hub Accounts
Cloud
# Analyzing How TeamTNT Used Compromised Docker Hub Accounts
Following our previous disclosure of compromised Docker hub accounts delivering cryptocurrency miners, we analyze these accounts and discover more malicious actions that you need to be aware of.
By: Trend Micro Research
2021/12/01
Read time: ( words)
Save to Folio
In early November, we disclosed that compromised Docker Hub accounts were being used for cryptocurrency mining and that these activities were tied to the TeamTNT threat actor. While those accounts have now been removed, we were still able to investigate TeamTNT’s activities in connection with these compromised accounts.
In addition to the behavior we noted earlier, we identified several other actions that the same threat actor carried out in different venue
Trendmicro
Analyzing How TeamTNT Used Compromised Docker Hub Accounts
blogs_trendmicro·2021-12-01
Analyzing How TeamTNT Used Compromised Docker Hub Accounts
Cloud
## Analyzing How TeamTNT Used Compromised Docker Hub Accounts
Following our previous disclosure of compromised Docker hub accounts delivering cryptocurrency miners, we analyze these accounts and discover more malicious actions that you need to be aware of.
By: Trend Micro Research 2021/12/01 Read time: ( words)
Save to Folio
In early November, we disclosed that compromised Docker Hub accounts were being used for cryptocurrency mining and that these activities were tied to the TeamTNT threat actor. While those accounts have now been removed, we were still able to investigate TeamTNT’s activities in connection with these compromised accounts.
In addition to the behavior we noted earlier, we identified several other actions that the same threat actor carried out in different venue
Bugzilla
CVE-2019-1002100 kube-apiserver: DoS with crafted patch of type json-patch
bugzilla·2019-02-26·CVSS 6.5
CVE-2019-1002100 [MEDIUM] CVE-2019-1002100 kube-apiserver: DoS with crafted patch of type json-patch
CVE-2019-1002100 kube-apiserver: DoS with crafted patch of type json-patch
A security issue was discovered in kube-apiserver versions before v1.11.8, v1.12.6, or v1.13.4. Users that are authorized to make patch requests to the Kubernetes API Server can send a specially crafted patch of type “json-patch” (e.g.`kubectl patch --type json` or `"Content-Type: application/json-patch+json"`) that consumes excessive resources while processing, causing a Denial of Service on the API Server.
Discussion:
References:
https://groups.google.com/forum/#!topic/kubernetes-announce/vmUUNkYfG9g
https://github.com/kubernetes/kubernetes/issues/74534
Upstream Patch:
https://github.com/kubernetes/kubernetes/pull/74000
---
Gluster ships kube-apiserver via heketi, however we don't use it to provision Gluster
http://www.securityfocus.com/bid/107290https://access.redhat.com/errata/RHSA-2019:1851https://access.redhat.com/errata/RHSA-2019:3239https://github.com/kubernetes/kubernetes/issues/74534https://groups.google.com/forum/#%21topic/kubernetes-announce/vmUUNkYfG9ghttps://security.netapp.com/advisory/ntap-20190416-0002/http://www.securityfocus.com/bid/107290https://access.redhat.com/errata/RHSA-2019:1851https://access.redhat.com/errata/RHSA-2019:3239https://github.com/kubernetes/kubernetes/issues/74534https://groups.google.com/forum/#%21topic/kubernetes-announce/vmUUNkYfG9ghttps://security.netapp.com/advisory/ntap-20190416-0002/
2019-04-01
Published