CVE-2022-31080
Last modified
CVE-2022-31080 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.1, 1.10.2, and 1.9.4, a large response received by the viaduct WSClient can cause a DoS from memory exhaustion. EPSS estimates a 0.62% chance of exploitation in the next 30 days.
Description
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.1, 1.10.2, and 1.9.4, a large response received by the viaduct WSClient can cause a DoS from memory exhaustion. The entire body of the response is being read into memory which could allow an attacker to send a request that returns a response with a large body. The consequence of the exhaustion is that the process which invokes a WSClient will be in a denial of service. The software is affected If users who are authenticated to the edge side connect to `cloudhub` from the edge side through WebSocket protocol. This bug has been fixed in Kubeedge 1.11.1, 1.10.2, and 1.9.4. There are currently no known workarounds.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linuxfoundation | Kubeedge | < 1.9.4 |
| Linuxfoundation | Kubeedge | >= 1.10.0, < 1.10.2 |
| Linuxfoundation | Kubeedge | >= 1.11.0, < 1.11.1 |
References
- https://github.com/kubeedge/kubeedge/security/advisories/GHSA-6wvc-6pww-qr4rThird Party Advisory
- https://github.com/kubeedge/kubeedge/security/advisories/GHSA-6wvc-6pww-qr4rThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-31080?
How severe is CVE-2022-31080?
How do I fix CVE-2022-31080?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-31075KubeEdge is an open source system for extending native conta…6.5
- CVE-2022-31076KubeEdge is built upon Kubernetes and extends native contain…5.7
- CVE-2022-31077KubeEdge is built upon Kubernetes and extends native contain…5.7
- CVE-2022-31078KubeEdge is an open source system for extending native conta…6.5
- CVE-2022-31079KubeEdge is an open source system for extending native conta…6.5
- CVE-2022-3108An issue was discovered in the Linux kernel through 5.16-rc6…5.5
- CVE-2022-31081HTTP::Daemon is a simple http server class written in perl. …6.5
- CVE-2022-31082GLPI is a Free Asset and IT Management Software package, Dat…9.8
- CVE-2022-31083Parse Server is an open source backend that can be deployed …7.5
- CVE-2022-31084LDAP Account Manager (LAM) is a webfrontend for managing ent…8.1
- CVE-2022-31085LDAP Account Manager (LAM) is a webfrontend for managing ent…6.1
- CVE-2022-31086LDAP Account Manager (LAM) is a webfrontend for managing ent…8.8
Are you affected by CVE-2022-31080?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
