CVE-2019-11254
published 2020-04-01CVE-2019-11254: The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an authorized user who sends malicious YAML…
PriorityP336medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
2.36%
81.9th percentile
The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an authorized user who sends malicious YAML payloads to cause the kube-apiserver to consume excessive CPU cycles while parsing YAML.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | kubernetes | < kubernetes 1.17.4-1 (bookworm) | kubernetes 1.17.4-1 (bookworm) |
| github.com | go-yaml_yaml | 0 – 2.1.0 | — |
| gopkg.in | yaml.v2 | >= 0 < 2.2.8 | 2.2.8 |
| kubernetes | kubernetes | < 1.15.10 | 1.15.10 |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | — | — |
| kubernetes | kubernetes | >= 0 < 1.17.4-1 | 1.17.4-1 |
| kubernetes | kubernetes | >= 0 < 1.17.4-1 | 1.17.4-1 |
| kubernetes | kubernetes | >= 0 < 1.17.4-1 | 1.17.4-1 |
| kubernetes | kubernetes | >= 0 < 1.17.4-1 | 1.17.4-1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Excessive Platform Resource Consumption within a Loop in Kubernetes
ghsa·2021-12-20
CVE-2019-11254 [MEDIUM] CWE-1050 Excessive Platform Resource Consumption within a Loop in Kubernetes
Excessive Platform Resource Consumption within a Loop in Kubernetes
The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an authorized user who sends malicious YAML payloads to cause the kube-apiserver to consume excessive CPU cycles while parsing YAML.
OSV
Excessive Platform Resource Consumption within a Loop in Kubernetes
osv·2021-12-20
CVE-2019-11254 [MEDIUM] Excessive Platform Resource Consumption within a Loop in Kubernetes
Excessive Platform Resource Consumption within a Loop in Kubernetes
The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an authorized user who sends malicious YAML payloads to cause the kube-apiserver to consume excessive CPU cycles while parsing YAML.
OSV
Excessive resource consumption in YAML parsing in gopkg.in/yaml.v2
osv·2021-04-14
CVE-2019-11254 Excessive resource consumption in YAML parsing in gopkg.in/yaml.v2
Excessive resource consumption in YAML parsing in gopkg.in/yaml.v2
Due to unbounded aliasing, a crafted YAML file can cause consumption of significant system resources. If parsing user supplied input, this may be used as a denial of service vector.
OSV
CVE-2019-11254: The Kubernetes API Server component in versions 1
osv·2020-04-01·CVSS 6.5
CVE-2019-11254 [MEDIUM] CVE-2019-11254: The Kubernetes API Server component in versions 1
The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an authorized user who sends malicious YAML payloads to cause the kube-apiserver to consume excessive CPU cycles while parsing YAML.
Red Hat
kubernetes: Denial of service in API server via crafted YAML payloads by authorized users
vendor_redhat·2020-03-27·CVSS 6.5
CVE-2019-11254 [MEDIUM] CWE-400 kubernetes: Denial of service in API server via crafted YAML payloads by authorized users
kubernetes: Denial of service in API server via crafted YAML payloads by authorized users
The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an authorized user who sends malicious YAML payloads to cause the kube-apiserver to consume excessive CPU cycles while parsing YAML.
Statement: The upstream Kubernetes fix for this vulnerability is to update the version of the Go dependency, gopkg.in/yaml.v2. This issue affects OpenShift Container Platform components that use versions before 2.2.8 of gopkg.in/yaml.v2 and accept YAML payloads.
Mitigation: Prevent unauthenticated or unauthorized access to the API server
Package: openshift4/ose-hypershift (Red Hat OpenShift Container Platform 4) - Will not fix
Package: openshift4/ose-k8s
Debian
CVE-2019-11254: kubernetes - The Kubernetes API Server component in versions 1.1-1.14, and versions prior to ...
vendor_debian·2019·CVSS 6.5
CVE-2019-11254 [MEDIUM] CVE-2019-11254: kubernetes - The Kubernetes API Server component in versions 1.1-1.14, and versions prior to ...
The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an authorized user who sends malicious YAML payloads to cause the kube-apiserver to consume excessive CPU cycles while parsing YAML.
Scope: local
bookworm: resolved (fixed in 1.17.4-1)
bullseye: resolved (fixed in 1.17.4-1)
forky: resolved (fixed in 1.17.4-1)
sid: resolved (fixed in 1.17.4-1)
trixie: resolved (fixed in 1.17.4-1)
No detection rules found.
No public exploits indexed.
arXiv
KGSecConfig: A Knowledge Graph Based Approach for Secured Container Orchestrator Configuration
arxiv_fulltext·2021-12-21
KGSecConfig: A Knowledge Graph Based Approach for Secured Container Orchestrator Configuration
KGSecConfig: A Knowledge Graph Based Approach for Secured Container Orchestrator Configuration
Mubin Ul Haque1, M. Mehdi Kholoosi2, and
M. Ali Babar3
Centre for Research on Engineering Software Technologies (CREST)
School of Computer Science, and Engineering, The University of Adelaide, Adelaide, Australia
Cyber Security Cooperative Research Centre
[email protected],
[email protected] [email protected]
plain
plain
## Abstract
Container Orchestrator (CO) is a vital technology for managing clusters of containers, which may form a virtualized infrastructure for developing and operating software systems. Like any other software system, securing CO is critical, but can be quite challenging task due to large number of configurable options. Manual configuration is
Bugzilla
CVE-2019-11254 kubernetes: Denial of service in API server via crafted YAML payloads by authorized users
bugzilla·2020-04-01·CVSS 6.5
CVE-2019-11254 [MEDIUM] CVE-2019-11254 kubernetes: Denial of service in API server via crafted YAML payloads by authorized users
CVE-2019-11254 kubernetes: Denial of service in API server via crafted YAML payloads by authorized users
A denial of service vulnerability was found in the kube-apiserver, allowing authorized users sending malicious YAML payloads to cause kube-apiserver to consume excessive CPU cycles while parsing YAML.
Upstream Issue:
https://github.com/kubernetes/kubernetes/issues/89535
Discussion:
External References:
https://groups.google.com/forum/#!topic/kubernetes-security-announce/wuwEwZigXBc
---
Mitigation:
Prevent unauthenticated or unauthorized access to the API server
---
Go yaml fix:
https://github.com/go-yaml/yaml/pull/555
---
- openshift4/ose-openshift-state-metrics-rhel7 does not accept YAML payloads
- openshift4/ose-k8s-prometheus-adapter only exposes a read-only API
---
https://github.com/kubernetes/kubernetes/issues/89535https://groups.google.com/d/msg/kubernetes-announce/ALL9s73E5ck/4yHe8J-PBAAJhttps://security.netapp.com/advisory/ntap-20200413-0003/https://github.com/kubernetes/kubernetes/issues/89535https://groups.google.com/d/msg/kubernetes-announce/ALL9s73E5ck/4yHe8J-PBAAJhttps://security.netapp.com/advisory/ntap-20200413-0003/
2020-04-01
Published