Oval Definition:oval:com.ubuntu.disco:def:2019112530000000
Revision Date:2019-10-17Version:1
Title:CVE-2019-11253 on Ubuntu 19.04 (disco) - medium.
Description:Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API server to consume excessive CPU or memory, potentially crashing and becoming unavailable. Prior to v1.14.0, default RBAC policy authorized anonymous users to submit requests that could trigger this vulnerability. Clusters upgraded from a version prior to v1.14.0 keep the more permissive policy by default for backwards compatibility.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2019-11253
Platform(s):Ubuntu 19.04
Product(s):
Definition Synopsis
  • Ubuntu 19.04 (disco) is installed.
  • AND kubernetes: while related to the CVE in some way, a decision has been made to ignore this issue.
  • BACK