CVE-2018-1330
HIGHApache Mesos 1.4.0-1.5.0 - Denial of Service via Malformed JSON Payload
Title source: llmDescription
When parsing a malformed JSON payload, libprocess in Apache Mesos versions 1.4.0 to 1.5.0 might crash due to an uncaught exception. Parsing chunked HTTP requests with trailers can lead to a libprocess crash too because of the mistakenly planted assertion. A malicious actor can therefore cause a denial of service of Mesos masters rendering the Mesos-controlled cluster inoperable.
References (1)
Core 1
Core References
Mailing List mailing-list
x_refsource_mlist
https://lists.apache.org/thread.html/395cb6bcf367702acd1e580a1f39b56cdd7a5953d0368b4c1adb1dde%40%3Cdev.mesos.apache.org%3E
Scores
CVSS v3
7.5
EPSS
0.0211
EPSS Percentile
84.3%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-20
Status
published
Products (4)
apache/mesos
1.4.0 rc1 (5 CPE variants)
apache/mesos
1.6.0 rc1
apache/mesos
1.4.0 - 1.4.2
org.apache.mesos/mesos
1.4.0 - 1.6.0Maven
Published
Sep 13, 2018
Tracked Since
Feb 18, 2026