CVE-2019-11254
01.04.2020, 21:15
The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an authorized user who sends malicious YAML payloads to cause the kube-apiserver to consume excessive CPU cycles while parsing YAML.Enginsight
| Vendor | Product | Version |
|---|---|---|
| kubernetes | kubernetes | 𝑥 < 1.15.10 |
| kubernetes | kubernetes | 1.16.0 ≤ 𝑥 < 1.16.7 |
| kubernetes | kubernetes | 1.17.0 ≤ 𝑥 < 1.17.3 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References