Description
A security issue was discovered in ingress-nginx where the validating admission controller feature is subject to a denial of service condition. By sending large requests to the validating admission controller, an attacker can cause memory consumption, which may result in the ingress-nginx controller pod being killed or the node running out of memory.
Problem types
CWE-770 Allocation of Resources Without Limits or Throttling
Product status
Any version before 1.13.7
Any version before 1.14.3
Credits
Matan Shabtay
References
github.com/kubernetes/kubernetes/issues/136680