PT-2024-17578 · Unknown · Cert-Manager

·

CVE-2024-12401

·

Published

2024-11-20

·

Updated

2026-06-26

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions cert-manager versions 0.1.0 through 1.16.1 cert-manager versions 1.15.0 through 1.15.3 cert-manager versions 1.12.0 through 1.12.13
Description A flaw exists in the cert-manager package where the pem.Decode() function can take an excessive amount of time to process specially crafted invalid PEM data. An attacker capable of modifying PEM data read by cert-manager, such as data within a Secret resource, can cause high CPU utilization in the cert-manager controller pod. This creates a denial-of-service (DoS) condition for the cert-manager instance within the cluster.
Recommendations Update to version 1.16.2. Update to version 1.15.4. Update to version 1.12.14. Ensure that RBAC is scoped correctly in the cluster to restrict users from modifying resources containing PEM data.

Exploit

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-54313
AZL-54324
CLEANSTART-2026-HV28992
CVE-2024-12401
GHSA-GHW8-3XQW-HHCJ
GHSA-R4PG-VG54-WXX4
GO-2024-3282
OPENSUSE-SU-2024:14599-1

Affected Products

Cert-Manager