CVE-2024-0793
Vulnerability Summary
Timeline
Description
A flaw was found in kube-controller-manager. This issue occurs when the initial application of a HPA config YAML lacking a .spec.behavior.scaleUp block causes a denial of service due to KCM pods going into restart churn.
CVSS Metrics
- v3.1•HIGH•Score: 7.7CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
EPSS Trends
Current EPSS score: 0.59%• Percentile: 47%
Techniques & Countermeasures
- CWE-20•Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Affected Systems
- chainguard•argo-cd-2.11
all
- chainguard•argocd-image-updater
< 0.17.0-r1
- chainguard•argocd-image-updater-fips
< 0.17.0-r2
- chainguard•aws-efs-csi-driver
< 2.1.1-r0
- chainguard•aws-efs-csi-driver-fips
< 2.1.1-r0
- wolfi•argocd-image-updater
< 0.17.0-r1
- wolfi•aws-efs-csi-driver
< 2.1.1-r0
- k8s.io•kubernetes
< 1.27.0-alpha.1
- redhat•openshift
< 0:4.12.0-202403042037.p0.g9946c63.assembly.stream.el8 | < 0:4.12.0-202403042037.p0.g9946c63.assembly.stream.el9
- redhat•openshift-hyperkube
< 0:4.12.0-202403042037.p0.g9946c63.assembly.stream.el8 | < 0:4.12.0-202403042037.p0.g9946c63.assembly.stream.el9
References (17)
- https://access.redhat.com/errata/RHSA-2024:0741
- https://access.redhat.com/errata/RHSA-2024:1267
- https://access.redhat.com/security/cve/CVE-2024-0793
- https://bugzilla.redhat.com/show_bug.cgi?id=2214402
- https://github.com/openshift/kubernetes/pull/1876
- https://nvd.nist.gov/vuln/detail/CVE-2024-0793
- https://github.com/kubernetes/kubernetes/issues/107038#issuecomment-1911327145
- https://github.com/kubernetes/kubernetes
- https://pkg.go.dev/vuln/GO-2024-3277
- https://github.com/advisories/GHSA-h7wq-jj8r-qm7p
- https://access.redhat.com/security/updates/classification/#important
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_1267.json
- https://www.cve.org/CVERecord?id=CVE-2024-0793
- https://access.redhat.com/downloads/content/package-browser/
- https://catalog.redhat.com/software/containers/
- https://github.com/kubernetes
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/0xxx/CVE-2024-0793.json