Allocation of Resources Without Limits or Throttling and Uncontrolled Memory Allocation in Kubernetes
Moderate severity
GitHub Reviewed
Published
Feb 15, 2022
to the GitHub Advisory Database
•
Updated Sep 18, 2023
Package
Affected versions
>= 1.15.0, < 1.15.10
>= 1.16.0, < 1.16.6
>= 1.17.0, < 1.17.2
Patched versions
1.15.10
1.16.6
1.17.2
Description
Published by the National Vulnerability Database
Mar 27, 2020
Reviewed
May 6, 2021
Published to the GitHub Advisory Database
Feb 15, 2022
Last updated
Sep 18, 2023
The Kubelet component in versions 1.15.0-1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via the kubelet API, including the unauthenticated HTTP read-only API typically served on port 10255, and the authenticated HTTPS API typically served on port 10250.
References