6.5 Medium
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
7.1 High
AI Score
Confidence
High
0.001 Low
EPSS
Percentile
23.6%
A vulnerability was fond in Knative Serving that could allow an attacker to crash the Knative Serving autoscaler resulting in a denial of service. The attacker would need to have compromised one pod in the Knative Serving deployment, and with that position they could launch the attack against the autoscaler.
When the autoscaler scrapes the metrics of pods, it sends a request to the /metrics
endpoint of each pod and reads the response. The attacker would need to detect the request from the autoscaler to the /metrics
endpoint of the pod they had compromised and send a malicious response back to the autoscaler. At this point, the autoscaler would crash. The root cause of the vulnerability was a memory exhaustion issue in the autoscaler that the attacker could trigger with the malicious reponse.
The vulnerability would allow a privilege escalation by the attacker from controlling one point to having negative impact on the entire Knative Serving deployment.
All users are vulnerable to this; Users that have not had any of their pods compromised are not at risk of this vulnerability.
The vulnerability has been patched in v1.10.5, v1.11.3 and v1.12.0
The vulnerability was reported by Ada Logics during an ongoing security audit of Knative involving Ada Logics, the Knative maintainers, OSTIF and CNCF.
CPE | Name | Operator | Version |
---|---|---|---|
knative.dev/serving | lt | 0.39.0 |
github.com/advisories/GHSA-qmvj-4qr9-v547
github.com/knative/serving/commit/012ee2509231b80b7842139bfabc30516d3026ca
github.com/knative/serving/commit/101f814112b9ca0767f457e7e616b46205551cf1
github.com/knative/serving/commit/fff40ef7bac9be8380ec3d1c70fc15b57093382a
github.com/knative/serving/security/advisories/GHSA-qmvj-4qr9-v547
nvd.nist.gov/vuln/detail/CVE-2023-48713
6.5 Medium
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
7.1 High
AI Score
Confidence
High
0.001 Low
EPSS
Percentile
23.6%