Lucene search

K
broadcomBroadcom Security ResponseBSNSA22717
HistoryNov 07, 2023 - 12:00 a.m.

YAML payloads to cause the kube-apiserver to consume excessive CPU cycles while parsing YAML (CVE-2019-11254)

2023-11-0700:00:00
Broadcom Security Response
support.broadcom.com
30
yaml payloads
kubernetes api server
cve-2019-11254
authorized user
cpu cycles

AI Score

7.9

Confidence

High

EPSS

0.001

Percentile

42.9%

The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an authorized user who sends malicious YAML payloads to cause the kube-apiserver to consume excessive CPU cycles while parsing YAML.