Denial of Service Vulnerability in Apache Mesos by Malicious JSON Payload
CVE-2018-1330
7.5HIGH
What is CVE-2018-1330?
Certain versions of Apache Mesos are susceptible to a vulnerability in libprocess that may be exploited when parsing malformed JSON payloads or chunked HTTP requests. An attacker can trigger an uncaught exception, causing a crash in the libprocess component. This can lead to denial of service for Mesos masters, disrupting the functionality of clusters managed by Mesos. Ensuring proper input validation and updating to patched versions can mitigate this risk.
Affected Version(s)
Apache Mesos 1.4.0 to 1.5.0