CVE-2023-32187
Published on: Not Yet Published
Last Modified on: 09/21/2023 03:21:00 PM UTC
Certain versions of K3s from K3s contain the following vulnerability:
An Allocation of Resources Without Limits or Throttling vulnerability in SUSE k3s allows attackers with access to K3s servers' apiserver/supervisor port (TCP 6443) cause denial of service. This issue affects k3s: from v1.24.0 before v1.24.17+k3s1, from v1.25.0 before v1.25.13+k3s1, from v1.26.0 before v1.26.8+k3s1, from sev1.27.0 before v1.27.5+k3s1, from v1.28.0 before v1.28.1+k3s1.
- CVE-2023-32187 has been assigned by
se[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
SUSE - k3s version < v1.24.17+k3s1
- Affected Vendor/Software:
SUSE - k3s version < v1.25.13+k3s1
- Affected Vendor/Software:
SUSE - k3s version < v1.26.8+k3s1
- Affected Vendor/Software:
SUSE - k3s version < v1.27.5+k3s1
- Affected Vendor/Software:
SUSE - k3s version < v1.28.1+k3s1
CVSS3 Score: 7.5 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | NONE | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
K3s apiserver port is vulnerable to unauthenticated remote denial-of-service (DoS) attack via TLS SAN stuffing attack · Advisory · k3s-io/k3s · GitHub | github.com text/html |
![]() |
Invalid Bug ID | bugzilla.suse.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | K3s | K3s | All | All | All | All |
- cpe:2.3:a:k3s:k3s:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE