CVE-2019-11254
01.04.2020, 21:15
The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an authorized user who sends malicious YAML payloads to cause the kube-apiserver to consume excessive CPU cycles while parsing YAML.Enginsight
Vendor | Product | Version |
---|---|---|
kubernetes | kubernetes | 𝑥 < 1.15.10 |
kubernetes | kubernetes | 1.16.0 ≤ 𝑥 < 1.16.7 |
kubernetes | kubernetes | 1.17.0 ≤ 𝑥 < 1.17.3 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References