CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 6.5. It affects Kubernetes. Public exploit code or proof-of-concept references have been detected in its references. Its EPSS score suggests a 10.4% probability of exploitation in the next 30 days. It may lead to a denial-of-service condition.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
In all Kubernetes versions prior to v1.11.8, v1.12.6, and v1.13.4, users that are authorized to make patch requests to the Kubernetes API Server can send a specially crafted patch of type "json-patch" (e.g. `kubectl patch --type json` or `"Content-Type: application/json-patch+json"`) that consumes excessive resources while processing, causing a Denial of Service on the API Server.
Related CVEs
Other vulnerabilities affecting the same vendor(s)