Launch Week Day 1: Announcing Security Design Review
HIGH 7.7 Go

Kubernetes Nil pointer dereference in KCM after v1 HPA patch request

GHSA-h7wq-jj8r-qm7p · CVE-2024-0793 · GO-2024-3277

Published · Modified

Description

A flaw was found in kube-controller-manager. This issue occurs when the initial application of a HPA config YAML lacking a .spec.behavior.scaleUp block causes a denial of service due to KCM pods going into restart churn.

Ready to move

Start Securing

Free, no credit card | First findings in minutes