HIGH 7.7 Go
Kubernetes Nil pointer dereference in KCM after v1 HPA patch request
GHSA-h7wq-jj8r-qm7p · CVE-2024-0793 · GO-2024-3277
Published · Modified
Description
A flaw was found in kube-controller-manager. This issue occurs when the initial application of a HPA config YAML lacking a .spec.behavior.scaleUp block causes a denial of service due to KCM pods going into restart churn.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2024-0793
- WEB https://github.com/kubernetes/kubernetes/issues/107038#issuecomment-1911327145
- WEB https://github.com/openshift/kubernetes/pull/1876
- WEB https://access.redhat.com/errata/RHSA-2024:0741
- WEB https://access.redhat.com/errata/RHSA-2024:1267
- WEB https://access.redhat.com/security/cve/CVE-2024-0793
- WEB https://bugzilla.redhat.com/show_bug.cgi?id=2214402
- PACKAGE https://github.com/kubernetes/kubernetes
- WEB https://pkg.go.dev/vuln/GO-2024-3277
Ready to move
Start Securing
Free, no credit card | First findings in minutes