PT-2026-107465 · Apache · Apache Yunikorn
CVSS v4.0
2.1
Low
| Vector | AV:N/AC:H/AT:P/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/S:N/AU:N/R:A/V:D/RE:H/U:Green |
Name of the Vulnerable Software and Affected Versions
Apache YuniKorn versions 1.8.0 through 1.9.x
Description
When configured with the LDAP group resolver, the server crashes due to an out-of-bounds read while processing group membership entries. This occurs if the LDAP server returns a
memberOf attribute for a user specified in the pod, and the membership record does not start with "CN=". This issue specifically affects installations using the non-default LDAP group provider.Recommendations
Upgrade to version 1.10.0.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Yunikorn