Hide Forgot
The parsing of YAML manifests by the Kubernetes API server could lead to a denial-of-service attack against a cluster’s Kubernetes API service, therefore leaving it vulnerable to an instance of a “billion laughs” attack. Upstream Issue: https://github.com/kubernetes/kubernetes/issues/83253 Reference: https://www.stackrox.com/post/2019/09/protecting-kubernetes-api-against-cve-2019-11253-billion-laughs-attack/
Created kubernetes tracking bugs for this issue: Affects: fedora-all [bug 1757702]
External References: https://www.stackrox.com/post/2019/09/protecting-kubernetes-api-against-cve-2019-11253-billion-laughs-attack/
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.1 Via RHSA-2019:3132 https://access.redhat.com/errata/RHSA-2019:3132
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2019-11253
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 3.10 Via RHSA-2019:3239 https://access.redhat.com/errata/RHSA-2019:3239
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 3.9 Via RHSA-2019:3811 https://access.redhat.com/errata/RHSA-2019:3811
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 3.11 Via RHSA-2019:3905 https://access.redhat.com/errata/RHSA-2019:3905
This issue has been addressed in the following products: OpenShift Service Mesh 1.1 Via RHSA-2020:2799 https://access.redhat.com/errata/RHSA-2020:2799
This issue has been addressed in the following products: OpenShift Service Mesh 1.1 Via RHSA-2020:2796 https://access.redhat.com/errata/RHSA-2020:2796
This issue has been addressed in the following products: OpenShift Service Mesh 1.1 Via RHSA-2020:2795 https://access.redhat.com/errata/RHSA-2020:2795
This issue has been addressed in the following products: OpenShift Service Mesh 1.0 Via RHSA-2020:2861 https://access.redhat.com/errata/RHSA-2020:2861
This issue has been addressed in the following products: OpenShift Service Mesh 1.0 Via RHSA-2020:2863 https://access.redhat.com/errata/RHSA-2020:2863
This issue has been addressed in the following products: OpenShift Service Mesh 1.0 Via RHSA-2020:2870 https://access.redhat.com/errata/RHSA-2020:2870
This issue has been addressed in the following products: Red Hat OpenStack Platform 16.2 Via RHSA-2022:2183 https://access.redhat.com/errata/RHSA-2022:2183