REDHAT-BUG-2327929: Low severity cert-manager cert-manager vulnerability
Published Nov 21, 2024
·Updated
cert-manager ha a potential slowdown / DoS when parsing specially crafted PEM inputs in github.com/cert-manager/cert-manager
Affected Software
1 affected component
cert-manager cert-manager
Event History
Nov 21, 2024
Data Sourced
via Red Hat·11:01 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2327929?
The severity of REDHAT-BUG-2327929 is classified as potentially high due to its ability to cause a denial of service through specially crafted PEM inputs.
2
How do I fix REDHAT-BUG-2327929?
To mitigate REDHAT-BUG-2327929, update to the latest version of cert-manager that addresses this vulnerability.
3
What are the symptoms of REDHAT-BUG-2327929?
Symptoms of REDHAT-BUG-2327929 include application slowdown or crashing when processing certain malicious PEM inputs.
4
Which versions of cert-manager are affected by REDHAT-BUG-2327929?
All versions of cert-manager prior to the patch for REDHAT-BUG-2327929 are affected, so upgrading is essential.
5
Is there a workaround for REDHAT-BUG-2327929?
Currently, there are no known effective workarounds for REDHAT-BUG-2327929 apart from applying the necessary updates.