Kubernetes kube-controller-manager vulnerability discovered
CVE-2024-0793
7.7HIGH
Summary
A vulnerability exists in the Kubernetes Controller Manager resulting from the initial application of a Horizontal Pod Autoscaler (HPA) configuration YAML that omits the .spec.behavior.scaleUp block. This flaw triggers a continuous restart cycle of KCM pods, leading to service disruption. When this configuration is applied, it causes the kube-controller-manager to enter a restart loop, which affects the overall stability of the Kubernetes environment. The implications of this issue highlight the importance of adhering to proper configuration practices to mitigate potential disruptions.
References
CVSS V3.1
Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published