CVE-2019-11254: Kubernetes API Server denial of service vulnerability from malicious YAML payloads
A denial of service vulnerability was found in the kube-apiserver, allowing authorized users sending malicious YAML payloads to cause kube-apiserver to consume excessive CPU cycles while parsing YAML.
Upstream Issue:
https://github.com/kubernetes/kubernetes/issues/89535
Other sources
The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an authorized user who sends malicious YAML payloads to cause the kube-apiserver to consume excessive CPU cycles while parsing YAML.
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2019-11254?
CVE-2019-11254 is a vulnerability in the Kubernetes API Server component that allows an authorized user to cause the kube-apiserver to consume excessive CPU cycles while parsing YAML payloads.
How does CVE-2019-11254 affect Kubernetes?
CVE-2019-11254 affects Kubernetes versions 1.1-1.14 and versions prior to 1.15.10, 1.16.7, and 1.17.3.
What is the severity of CVE-2019-11254?
CVE-2019-11254 has a severity rating of 6.5 (medium).
How can I fix CVE-2019-11254?
To fix CVE-2019-11254, update your Kubernetes version to 1.15.10, 1.16.7, or 1.17.3.
Where can I find more information about CVE-2019-11254?
You can find more information about CVE-2019-11254 on the CVE website, NIST's vulnerability database, and Red Hat's security advisories.