First published: Thu Oct 17 2024(Updated: )
A denial of service (DoS) vulnerability was found in OpenShift. This flaw allows attackers to exploit the GraphQL batching functionality. The vulnerability arises when multiple queries can be sent within a single request, enabling an attacker to submit a request containing thousands of aliases in one query. This issue causes excessive resource consumption, leading to application unavailability for legitimate users.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat OpenShift Container Platform | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-50311 is classified as a denial of service (DoS) vulnerability.
To address CVE-2024-50311, update your Red Hat OpenShift Container Platform to the latest version that resolves this vulnerability.
CVE-2024-50311 allows attackers to send multiple queries in a single request, leading to potential service disruption.
CVE-2024-50311 affects Red Hat OpenShift Container Platform version 4.0.
Currently, there are no specific workarounds available for mitigating CVE-2024-50311 other than applying the recommended updates.