A malicious network-policy configuration can cause Openshift Routing to crash when using ovs-network policy plugin. An attacker can use this flaw to cause a Denial of Service (DoS) attack on an Openshift 3.9 Cluster.
The ovs-networkpolicy plugin was tech preview until the 3.7 release, ref: https://docs.openshift.com/container-platform/3.6/install_config/configuring_sdn.html
Acknowledgments: Name: Taichi Kageyama (NEC)
Mitigation: Use an alternative plugin such as ovs-subnet, or ovs-multitentant if delivering a multitentant service.
OCP 3.10.0 Reference: https://bugzilla.redhat.com/show_bug.cgi?id=1743747