The Kubernetes Authors

3 exploits Active since Nov 2018
CVE-2021-23017 NOMISEC HIGH STUB
nginx - Memory Corruption
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.
1 stars
CVSS 7.7
CVE-2019-9511 NOMISEC HIGH WORKING POC
HTTP/2 - DoS
Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to queue the data in 1-byte chunks. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.
CVSS 7.5
CVE-2018-16843 NOMISEC HIGH WORKING POC
nginx <1.15.6, 1.14.1 - Memory Corruption
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.
CVSS 7.5