K8S.Io Apimachinery vulnerabilities
2 known vulnerabilities affecting k8s.io/apimachinery.
Total CVEs
2
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2020-8559MEDIUM≥ 0, < 0.16.13≥ 0.17.0, < 0.17.9+1 more2024-04-24
CVE-2020-8559 [MEDIUM] CWE-601 Privilege Escalation in Kubernetes
Privilege Escalation in Kubernetes
The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.7 are vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise to a full cluster compromise.
ghsaosv
CVE-2019-11253HIGHCVSS 7.5PoC≥ 0, < 0.0.0-20190927203648-9ce6eca90e732023-02-08
CVE-2019-11253 [HIGH] CWE-20 Kubernetes apimachinery packages vulnerable to unbounded recursion in JSON or YAML parsing
Kubernetes apimachinery packages vulnerable to unbounded recursion in JSON or YAML parsing
CVE-2019-11253 is a denial of service vulnerability in the kube-apiserver, allowing authorized users sending malicious YAML or JSON payloads to cause kube-apiserver to consume excessive CPU or memory, potentially crashing and becoming unavailable.
When creating a ConfigMap object which
ghsaosv