CVE-2018-1330

HIGH

Apache Mesos 1.4.0-1.5.0 - Denial of Service via Malformed JSON Payload

Title source: llm
STIX 2.1

Description

When parsing a malformed JSON payload, libprocess in Apache Mesos versions 1.4.0 to 1.5.0 might crash due to an uncaught exception. Parsing chunked HTTP requests with trailers can lead to a libprocess crash too because of the mistakenly planted assertion. A malicious actor can therefore cause a denial of service of Mesos masters rendering the Mesos-controlled cluster inoperable.

References (1)

Core 1

Scores

CVSS v3 7.5
EPSS 0.0211
EPSS Percentile 84.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-20
Status published
Products (4)
apache/mesos 1.4.0 rc1 (5 CPE variants)
apache/mesos 1.6.0 rc1
apache/mesos 1.4.0 - 1.4.2
org.apache.mesos/mesos 1.4.0 - 1.6.0Maven
Published Sep 13, 2018
Tracked Since Feb 18, 2026