SecBoard
Zurück zur CVE-Übersicht

CVE-2024-12401

MEDIUM(4.4)

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H

Risk Signal Score11/100 — NIEDRIG
  • CVSS 4.4 — Mittel

EPSS-Score

1%

Exploit-Wahrscheinlichkeit (30 Tage)

CVSS Score

4.4

Technische Schwere

Beschreibung

A flaw was found in the cert-manager package. This flaw allows an attacker who can modify PEM data that the cert-manager reads, for example, in a Secret resource, to use large amounts of CPU in the cert-manager controller pod to effectively create a denial-of-service (DoS) vector for the cert-manager in the cluster.

Referenzen