CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
Percentile
34.3%
An Allocation of Resources Without Limits or Throttling vulnerability in SUSE k3s allows attackers with access to K3s servers’ apiserver/supervisor port (TCP 6443) cause denial of service.
This issue affects k3s: from v1.24.0 before v1.24.17+k3s1, from v1.25.0 before v1.25.13+k3s1, from v1.26.0 before v1.26.8+k3s1, from sev1.27.0 before v1.27.5+k3s1, from v1.28.0 before v1.28.1+k3s1.
[
{
"defaultStatus": "unaffected",
"packageName": "k3s",
"product": "k3s",
"vendor": "SUSE",
"versions": [
{
"lessThan": "v1.24.17+k3s1",
"status": "affected",
"version": "v1.24.0",
"versionType": "semver"
},
{
"lessThan": "v1.25.13+k3s1",
"status": "affected",
"version": "v1.25.0",
"versionType": "semver"
},
{
"lessThan": "v1.26.8+k3s1",
"status": "affected",
"version": "v1.26.0",
"versionType": "semver"
},
{
"lessThan": "v1.27.5+k3s1",
"status": "affected",
"version": "sev1.27.0",
"versionType": "semver"
},
{
"lessThan": "v1.28.1+k3s1",
"status": "affected",
"version": "v1.28.0",
"versionType": "semver"
}
]
}
]