Rapid7 Vulnerability & Exploit Database

Red Hat OpenShift: CVE-2020-8552: kubernetes: Use of unbounded 'client' label in apiserver_request_total allows for memory exhaustion

Free InsightVM Trial No Credit Card Necessary
Watch Demo See how it all works
Back to Search

Red Hat OpenShift: CVE-2020-8552: kubernetes: Use of unbounded 'client' label in apiserver_request_total allows for memory exhaustion

Severity
4
CVSS
(AV:N/AC:L/Au:S/C:N/I:N/A:P)
Published
03/27/2020
Created
04/03/2020
Added
04/02/2020
Modified
05/10/2023

Description

The Kubernetes API server component in versions prior to 1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via successful API requests.

Solution(s)

  • linuxrpm-upgrade-atomic-enterprise-service-catalog
  • linuxrpm-upgrade-atomic-openshift
  • linuxrpm-upgrade-atomic-openshift-cluster-autoscaler
  • linuxrpm-upgrade-atomic-openshift-descheduler
  • linuxrpm-upgrade-atomic-openshift-dockerregistry
  • linuxrpm-upgrade-atomic-openshift-metrics-server
  • linuxrpm-upgrade-atomic-openshift-node-problem-detector
  • linuxrpm-upgrade-atomic-openshift-service-idler
  • linuxrpm-upgrade-cri-o
  • linuxrpm-upgrade-dracut
  • linuxrpm-upgrade-golang-github-openshift-oauth-proxy
  • linuxrpm-upgrade-golang-github-prometheus-alertmanager
  • linuxrpm-upgrade-golang-github-prometheus-node_exporter
  • linuxrpm-upgrade-golang-github-prometheus-prometheus
  • linuxrpm-upgrade-ignition
  • linuxrpm-upgrade-iptables
  • linuxrpm-upgrade-libnftnl
  • linuxrpm-upgrade-machine-config-daemon
  • linuxrpm-upgrade-openshift
  • linuxrpm-upgrade-openshift-ansible
  • linuxrpm-upgrade-openshift-clients
  • linuxrpm-upgrade-openshift-enterprise-autoheal
  • linuxrpm-upgrade-openshift-enterprise-cluster-capacity
  • linuxrpm-upgrade-openshift-kuryr
  • linuxrpm-upgrade-ostree
  • linuxrpm-upgrade-rpm-ostree
  • linuxrpm-upgrade-systemd
  • linuxrpm-upgrade-toolbox

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;