PT-2024-17578 · Unknown · Cert-Manager
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
cert-manager versions 0.1.0 through 1.16.1
cert-manager versions 1.15.0 through 1.15.3
cert-manager versions 1.12.0 through 1.12.13
Description
A flaw exists in the cert-manager package where the
pem.Decode() function can take an excessive amount of time to process specially crafted invalid PEM data. An attacker capable of modifying PEM data read by cert-manager, such as data within a Secret resource, can cause high CPU utilization in the cert-manager controller pod. This creates a denial-of-service (DoS) condition for the cert-manager instance within the cluster.Recommendations
Update to version 1.16.2.
Update to version 1.15.4.
Update to version 1.12.14.
Ensure that RBAC is scoped correctly in the cluster to restrict users from modifying resources containing PEM data.
Exploit
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cert-Manager