HIGH 7.7 Go

Kubernetes Nil pointer dereference in KCM after v1 HPA patch request

GHSA-h7wq-jj8r-qm7p · CVE-2024-0793 · GO-2024-3277

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

A flaw was found in kube-controller-manager. This issue occurs when the initial application of a HPA config YAML lacking a .spec.behavior.scaleUp block causes a denial of service due to KCM pods going into restart churn.

Ready to move

Start Securing

Free, no credit card | First findings in minutes