CVE-2024-0793

CVSS 3.1 Score 7.7 of 10 (high)

Details

Published Nov 17, 2024
Updated: Nov 18, 2024
CWE ID 20

Summary

CVE-2024-0793 is a newly identified vulnerability affecting the kube-controller-manager in Kubernetes environments. This issue arises when a Horizontal Pod Autoscaler (HPA) configuration file fails to include the necessary .spec.behavior.scaleUp block. As a result, the absence of this block triggers a denial of service condition, leading to an excessive number of pod restarts in KCM. This churn can impact the overall performance and availability of the Kubernetes cluster.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share