{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-23T02:11:40.003","vulnerabilities":[{"cve":{"id":"CVE-2019-11253","sourceIdentifier":"jordan@liggitt.net","published":"2019-10-17T16:15:10.443","lastModified":"2026-02-24T20:23:48.367","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API server to consume excessive CPU or memory, potentially crashing and becoming unavailable. Prior to v1.14.0, default RBAC policy authorized anonymous users to submit requests that could trigger this vulnerability. Clusters upgraded from a version prior to v1.14.0 keep the more permissive policy by default for backwards compatibility."},{"lang":"es","value":"La comprobación de entrada inapropiada en el servidor API de Kubernetes en las versiones v1.0 hasta 1.12 y versiones anteriores a v1.13.12, v1.14.8, v1.15.5 y v1.16.2, permite a los usuarios autorizados enviar cargas maliciosas de YAML o JSON, causando que el servidor API consuma demasiada CPU o memoria, fallando potencialmente y dejando de estar disponible. En versiones anteriores a v1.14.0, la política predeterminada de RBAC autorizaba a los usuarios anónimos para enviar peticiones que pudieran desencadenar esta vulnerabilidad. Los clústeres actualizados desde una versión anterior a v1.14.0 mantienen la política más permisiva por defecto para la compatibilidad con versiones anteriores."}],"metrics":{"cvssMetricV31":[{"source":"jordan@liggitt.net","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"jordan@liggitt.net","type":"Secondary","description":[{"lang":"en","value":"CWE-20"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-776"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*","versionStartIncluding":"1.1.0","versionEndIncluding":"1.12.10","matchCriteriaId":"F0820894-56B7-4CB8-AE5C-29639FA59718"},{"vulnerable":true,"criteria":"cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*","versionStartIncluding":"1.13.0","versionEndExcluding":"1.13.12","matchCriteriaId":"C4C87C13-A72F-4930-88DD-658099449303"},{"vulnerable":true,"criteria":"cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*","versionStartIncluding":"1.14.0","versionEndExcluding":"1.14.8","matchCriteriaId":"ADA3952E-8133-4E6A-A365-4FD74ABA962C"},{"vulnerable":true,"criteria":"cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*","versionStartIncluding":"1.15.0","versionEndExcluding":"1.15.5","matchCriteriaId":"F9F7837F-DA69-453E-8B24-1EDF0A5CAB4C"},{"vulnerable":true,"criteria":"cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*","versionStartIncluding":"1.16.0","versionEndExcluding":"1.16.2","matchCriteriaId":"E1BDF819-871C-4E34-978F-BAFF8D895B84"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:openshift_container_platform:3.9:*:*:*:*:*:*:*","matchCriteriaId":"309CB6F8-F178-454C-BE97-787F78647C28"},{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:openshift_container_platform:3.10:*:*:*:*:*:*:*","matchCriteriaId":"4DBCD38F-BBE8-488C-A8C3-5782F191D915"},{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*","matchCriteriaId":"2F87326E-0B56-4356-A889-73D026DB1D4B"}]}]}],"references":[{"url":"https://access.redhat.com/errata/RHSA-2019:3239","source":"jordan@liggitt.net","tags":["Third Party Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2019:3811","source":"jordan@liggitt.net","tags":["Third Party Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2019:3905","source":"jordan@liggitt.net","tags":["Third Party Advisory"]},{"url":"https://github.com/kubernetes/kubernetes/issues/83253","source":"jordan@liggitt.net","tags":["Exploit","Issue Tracking","Mitigation","Third Party Advisory"]},{"url":"https://groups.google.com/forum/#%21topic/kubernetes-security-announce/jk8polzSUxs","source":"jordan@liggitt.net","tags":["Permissions Required"]},{"url":"https://security.netapp.com/advisory/ntap-20191031-0006/","source":"jordan@liggitt.net","tags":["Third Party Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2019:3239","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2019:3811","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2019:3905","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://github.com/kubernetes/kubernetes/issues/83253","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Mitigation","Third Party Advisory"]},{"url":"https://groups.google.com/forum/#%21topic/kubernetes-security-announce/jk8polzSUxs","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]},{"url":"https://security.netapp.com/advisory/ntap-20191031-0006/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}}]}