Kubernetes kube-controller-manager vulnerability discovered
CVE-2024-0793

7.7HIGH

Key Information:

Vendor
kubernetes
Vendor
CVE Published:
17 November 2024

Summary

A vulnerability exists in the Kubernetes Controller Manager resulting from the initial application of a Horizontal Pod Autoscaler (HPA) configuration YAML that omits the .spec.behavior.scaleUp block. This flaw triggers a continuous restart cycle of KCM pods, leading to service disruption. When this configuration is applied, it causes the kube-controller-manager to enter a restart loop, which affects the overall stability of the Kubernetes environment. The implications of this issue highlight the importance of adhering to proper configuration practices to mitigate potential disruptions.

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

.