CVE-2019-11254: Kubernetes API Server denial of service vulnerability from malicious YAML payloads
A denial of service vulnerability was found in the kube-apiserver, allowing authorized users sending malicious YAML payloads to cause kube-apiserver to consume excessive CPU cycles while parsing YAML.
Upstream Issue:
https://github.com/kubernetes/kubernetes/issues/89535
Other sources
The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an authorized user who sends malicious YAML payloads to cause the kube-apiserver to consume excessive CPU cycles while parsing YAML.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/atomic-openshiftto a version that resolves this vulnerability.Fixed in 0:3.11.232-1.git.0.a5bc32f.el7 - Upgrade
Upgrade
redhat/openshiftto a version that resolves this vulnerability.Fixed in 0:4.5.0-202007012112.p0.git.0.582d7fc.el8 - Upgrade
Upgrade
redhat/kubernetesto a version that resolves this vulnerability.Fixed in 1.17.3 - Upgrade
Upgrade
redhat/kubernetesto a version that resolves this vulnerability.Fixed in 1.16.7 - Upgrade
Upgrade
redhat/kubernetesto a version that resolves this vulnerability.Fixed in 1.15.10 - Upgrade
Upgrade
kube-apiserverto a version that resolves this vulnerability.Fixed in 1.15.10 - Upgrade
Upgrade
kube-apiserverto a version that resolves this vulnerability.Fixed in 1.16.7 - Upgrade
Upgrade
kube-apiserverto a version that resolves this vulnerability.Fixed in 1.17.3 - Compensating control
Prevent unauthenticated or unauthorized access to the Kubernetes API server so only authorized users can send requests.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2019-11254?
CVE-2019-11254 is a vulnerability in the Kubernetes API Server component that allows an authorized user to cause the kube-apiserver to consume excessive CPU cycles while parsing YAML payloads.
How does CVE-2019-11254 affect Kubernetes?
CVE-2019-11254 affects Kubernetes versions 1.1-1.14 and versions prior to 1.15.10, 1.16.7, and 1.17.3.
What is the severity of CVE-2019-11254?
CVE-2019-11254 has a severity rating of 6.5 (medium).
How can I fix CVE-2019-11254?
To fix CVE-2019-11254, update your Kubernetes version to 1.15.10, 1.16.7, or 1.17.3.
Where can I find more information about CVE-2019-11254?
You can find more information about CVE-2019-11254 on the CVE website, NIST's vulnerability database, and Red Hat's security advisories.