CVE-2019-11253
published 2019-10-17CVE-2019-11253: Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized…
PriorityP262high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EXPLOIT
EPSS
25.94%
97.8th percentile
Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API server to consume excessive CPU or memory, potentially crashing and becoming unavailable. Prior to v1.14.0, default RBAC policy authorized anonymous users to submit requests that could trigger this vulnerability. Clusters upgraded from a version prior to v1.14.0 keep the more permissive policy by default for backwards compatibility.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | kubernetes | < kubernetes 1.17.4-1 (bookworm) | kubernetes 1.17.4-1 (bookworm) |
| k8s.io | apimachinery | >= 0 < 0.0.0-20190927203648-9ce6eca90e73 | 0.0.0-20190927203648-9ce6eca90e73 |
| k8s.io | kubernetes | >= 1.0.0 < 1.13.12 | 1.13.12 |
| k8s.io | kubernetes | >= 1.14.0 < 1.14.8 | 1.14.8 |
| k8s.io | kubernetes | >= 1.15.0 < 1.15.5 | 1.15.5 |
| k8s.io | kubernetes | >= 1.16.0 < 1.16.2 | 1.16.2 |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | >= 0 < 1.17.4-1 | 1.17.4-1 |
| kubernetes | kubernetes | >= 0 < 1.17.4-1 | 1.17.4-1 |
| kubernetes | kubernetes | >= 0 < 1.17.4-1 | 1.17.4-1 |
Detection & IOCsextracted from sources · hover to see the quote
- →HTTP POST to /apis/authorization.k8s.io/v1/selfsubjectaccessreviews with Content-Type: application/yaml carrying a Billion Laughs YAML payload triggers the vulnerability; a 422 response containing 'Invalid value' and 'FieldValueInvalid' confirms a vulnerable endpoint. ↗
- →Response body containing the words 'Invalid value', 'FieldValueInvalid', and HTTP status '422' together (AND condition) indicates a vulnerable Kubernetes API server. ↗
- →Prior to Kubernetes v1.14.0, default RBAC policy authorized anonymous users to submit requests that could trigger this vulnerability — clusters upgraded from pre-v1.14.0 retain this permissive policy by default. ↗
- →The attack vector is network-accessible (AV:N), requires no authentication (PR:N) and no user interaction (UI:N), making unauthenticated remote exploitation possible on unpatched pre-v1.14.0 clusters. ↗
- →Upstream issue tracker reference for payload samples and further technical detail. ↗
- →PoC/payload reference hosted on GitHub Gist by bgeesaman — contains a concrete Billion Laughs YAML payload for the Kubernetes API server. ↗
- ·Clusters running Kubernetes v1.0–v1.12 are all affected; fixed versions are v1.13.12, v1.14.8, v1.15.5, and v1.16.2 or later. ↗
- ·Clusters upgraded from a version prior to v1.14.0 retain the permissive anonymous-access RBAC policy by default, widening the attack surface even after an upgrade. ↗
- ·The nuclei template targets a single request (max-request: 1) to the selfsubjectaccessreviews endpoint; detection relies on a 422 response body, not on observing resource exhaustion. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
ghsa7.5HIGH
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kubernetes: YAML parsing vulnerable to "Billion Laughs" attack, allowing for remote denial of service
vendor_redhat·2019-09-28·CVSS 7.5
CVE-2019-11253 [HIGH] CWE-400 kubernetes: YAML parsing vulnerable to "Billion Laughs" attack, allowing for remote denial of service
kubernetes: YAML parsing vulnerable to "Billion Laughs" attack, allowing for remote denial of service
Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API server to consume excessive CPU or memory, potentially crashing and becoming unavailable. Prior to v1.14.0, default RBAC policy authorized anonymous users to submit requests that could trigger this vulnerability. Clusters upgraded from a version prior to v1.14.0 keep the more permissive policy by default for backwards compatibility.
A flaw was found kubernetes. The parsing of YAML manifests by the Kubernetes API server could lead to a denial-of-service attack leaving it v
Debian
CVE-2019-11253: kubernetes - Improper input validation in the Kubernetes API server in versions v1.0-1.12 and...
vendor_debian·2019·CVSS 7.5
CVE-2019-11253 [HIGH] CVE-2019-11253: kubernetes - Improper input validation in the Kubernetes API server in versions v1.0-1.12 and...
Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API server to consume excessive CPU or memory, potentially crashing and becoming unavailable. Prior to v1.14.0, default RBAC policy authorized anonymous users to submit requests that could trigger this vulnerability. Clusters upgraded from a version prior to v1.14.0 keep the more permissive policy by default for backwards compatibility.
Scope: local
bookworm: resolved (fixed in 1.17.4-1)
bullseye: resolved (fixed in 1.17.4-1)
forky: resolved (fixed in 1.17.4-1)
sid: resolved (fixed in 1.17.4-1)
trixie: resolved (fixed in 1.17.4-1)
OSV
XML Entity Expansion and Improper Input Validation in Kubernetes API server in k8s.io/kubernetes
osv·2024-08-21
CVE-2019-11253 XML Entity Expansion and Improper Input Validation in Kubernetes API server in k8s.io/kubernetes
XML Entity Expansion and Improper Input Validation in Kubernetes API server in k8s.io/kubernetes
XML Entity Expansion and Improper Input Validation in Kubernetes API server in k8s.io/kubernetes
OSV
Kubernetes apimachinery packages vulnerable to unbounded recursion in JSON or YAML parsing
osv·2023-02-08·CVSS 7.5
CVE-2019-11253 [HIGH] Kubernetes apimachinery packages vulnerable to unbounded recursion in JSON or YAML parsing
Kubernetes apimachinery packages vulnerable to unbounded recursion in JSON or YAML parsing
CVE-2019-11253 is a denial of service vulnerability in the kube-apiserver, allowing authorized users sending malicious YAML or JSON payloads to cause kube-apiserver to consume excessive CPU or memory, potentially crashing and becoming unavailable.
When creating a ConfigMap object which has recursive references contained in it, excessive CPU usage can occur. This appears to be an instance of a "Billion Laughs" attack which is quite well known as an XML parsing issue.
Applying this manifest to a cluster causes the client to hang for some time with considerable CPU usage.
```yaml
apiVersion: v1
data:
a: &a ["web","web","web","web","web","web","web","web","web"]
b: &b [*a,*a,*a,*a,*a,*a,*a,*a,*a]
c:
GHSA
Kubernetes apimachinery packages vulnerable to unbounded recursion in JSON or YAML parsing
ghsa·2023-02-08·CVSS 7.5
CVE-2019-11253 [HIGH] CWE-20 Kubernetes apimachinery packages vulnerable to unbounded recursion in JSON or YAML parsing
Kubernetes apimachinery packages vulnerable to unbounded recursion in JSON or YAML parsing
CVE-2019-11253 is a denial of service vulnerability in the kube-apiserver, allowing authorized users sending malicious YAML or JSON payloads to cause kube-apiserver to consume excessive CPU or memory, potentially crashing and becoming unavailable.
When creating a ConfigMap object which has recursive references contained in it, excessive CPU usage can occur. This appears to be an instance of a "Billion Laughs" attack which is quite well known as an XML parsing issue.
Applying this manifest to a cluster causes the client to hang for some time with considerable CPU usage.
```yaml
apiVersion: v1
data:
a: &a ["web","web","web","web","web","web","web","web","web"]
b: &b [*a,*a,*a,*a,*a,*a,*a,*a,*a]
c:
OSV
XML Entity Expansion and Improper Input Validation in Kubernetes API server
osv·2021-05-18
CVE-2019-11253 [HIGH] XML Entity Expansion and Improper Input Validation in Kubernetes API server
XML Entity Expansion and Improper Input Validation in Kubernetes API server
Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API server to consume excessive CPU or memory, potentially crashing and becoming unavailable. Prior to v1.14.0, default RBAC policy authorized anonymous users to submit requests that could trigger this vulnerability. Clusters upgraded from a version prior to v1.14.0 keep the more permissive policy by default for backwards compatibility.
### Specific Go Packages Affected
k8s.io/kubernetes/pkg/apiserver
GHSA
XML Entity Expansion and Improper Input Validation in Kubernetes API server
ghsa·2021-05-18
CVE-2019-11253 [HIGH] CWE-20 XML Entity Expansion and Improper Input Validation in Kubernetes API server
XML Entity Expansion and Improper Input Validation in Kubernetes API server
Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API server to consume excessive CPU or memory, potentially crashing and becoming unavailable. Prior to v1.14.0, default RBAC policy authorized anonymous users to submit requests that could trigger this vulnerability. Clusters upgraded from a version prior to v1.14.0 keep the more permissive policy by default for backwards compatibility.
### Specific Go Packages Affected
k8s.io/kubernetes/pkg/apiserver
OSV
CVE-2019-11253: Improper input validation in the Kubernetes API server in versions v1
osv·2019-10-17·CVSS 7.5
CVE-2019-11253 [HIGH] CVE-2019-11253: Improper input validation in the Kubernetes API server in versions v1
Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API server to consume excessive CPU or memory, potentially crashing and becoming unavailable. Prior to v1.14.0, default RBAC policy authorized anonymous users to submit requests that could trigger this vulnerability. Clusters upgraded from a version prior to v1.14.0 keep the more permissive policy by default for backwards compatibility.
No detection rules found.
Nuclei
Kubernetes API Server - YAML Parsing DoS (Billion Laughs)
nuclei·CVSS 7.5
CVE-2019-11253 [HIGH] Kubernetes API Server - YAML Parsing DoS (Billion Laughs)
Kubernetes API Server - YAML Parsing DoS (Billion Laughs)
The Kubernetes API server is vulnerable to a denial of service attack via YAML/JSON parsing. An attacker can send a specially crafted YAML/JSON payload that causes exponential memory consumption (Billion Laughs attack), leading to API server crash.
Template:
id: CVE-2019-11253
info:
name: Kubernetes API Server - YAML Parsing DoS (Billion Laughs)
author: ritikchaddha
severity: high
description: |
The Kubernetes API server is vulnerable to a denial of service attack via YAML/JSON parsing. An attacker can send a specially crafted YAML/JSON payload that causes exponential memory consumption (Billion Laughs attack), leading to API server crash.
impact: |
Attackers can cause the API server to crash or become unavailable by consuming e
Bugzilla
CVE-2019-11253 kubernetes: YAML parsing vulnerable to "Billion Laughs" attack, allowing for remote denial of service [fedora-all]
bugzilla·2019-10-02·CVSS 7.5
CVE-2019-11253 [HIGH] CVE-2019-11253 kubernetes: YAML parsing vulnerable to "Billion Laughs" attack, allowing for remote denial of service [fedora-all]
CVE-2019-11253 kubernetes: YAML parsing vulnerable to "Billion Laughs" attack, allowing for remote denial of service [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Bugzilla
CVE-2019-11253 kubernetes: YAML parsing vulnerable to "Billion Laughs" attack, allowing for remote denial of service
bugzilla·2019-10-02·CVSS 7.5
CVE-2019-11253 [HIGH] CVE-2019-11253 kubernetes: YAML parsing vulnerable to "Billion Laughs" attack, allowing for remote denial of service
CVE-2019-11253 kubernetes: YAML parsing vulnerable to "Billion Laughs" attack, allowing for remote denial of service
The parsing of YAML manifests by the Kubernetes API server could lead to a denial-of-service attack against a cluster’s Kubernetes API service, therefore leaving it vulnerable to an instance of a “billion laughs” attack.
Upstream Issue:
https://github.com/kubernetes/kubernetes/issues/83253
Reference:
https://www.stackrox.com/post/2019/09/protecting-kubernetes-api-against-cve-2019-11253-billion-laughs-attack/
Discussion:
Created kubernetes tracking bugs for this issue:
Affects: fedora-all [bug 1757702]
---
External References:
https://www.stackrox.com/post/2019/09/protecting-kubernetes-api-against-cve-2019-11253-billion-laughs-attack/
---
This issue has been ad
arXiv
XI Commandments of Kubernetes Security: A Systematization of Knowledge Related to Kubernetes Security Practices
arxiv_fulltext·2020-06-27
XI Commandments of Kubernetes Security: A Systematization of Knowledge Related to Kubernetes Security Practices
11 Commandments of Kubernetes Security: A Systematization of Knowledge Related to Kubernetes Security Practices
Md. Shazibul Islam Shamim
Dept. of Computer Science
Tennessee Technological University
Cookeville, TN, USA
[email protected]
Farzana Ahamed Bhuiyan
Dept. of Computer Science
Tennessee Technological University
Cookeville, TN, USA
[email protected]
Akond Rahman
Dept. of Computer Science
Tennessee Tech. University
Cookeville, TN, USA
[email protected]
## Abstract
Kubernetes is an open-source software for automating management of computerized services. Organizations, such as IBM, Capital One and Adidas use Kubernetes to deploy and manage their containers, and have reported benefits related to deployment frequency. Despite reported benefits, Kub
https://access.redhat.com/errata/RHSA-2019:3239https://access.redhat.com/errata/RHSA-2019:3811https://access.redhat.com/errata/RHSA-2019:3905https://github.com/kubernetes/kubernetes/issues/83253https://groups.google.com/forum/#%21topic/kubernetes-security-announce/jk8polzSUxshttps://security.netapp.com/advisory/ntap-20191031-0006/https://access.redhat.com/errata/RHSA-2019:3239https://access.redhat.com/errata/RHSA-2019:3811https://access.redhat.com/errata/RHSA-2019:3905https://github.com/kubernetes/kubernetes/issues/83253https://groups.google.com/forum/#%21topic/kubernetes-security-announce/jk8polzSUxshttps://security.netapp.com/advisory/ntap-20191031-0006/
2019-10-17
Published