Description
Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.22, Handler in dataclients/kubernetes/admission/admission.go passes the body of requests to the Kubernetes admission endpoint at :9443/admission directly to io.ReadAll(r.Body) without a size limit. An attacker with in-cluster network access and a valid Kubernetes client certificate can send a very large body that causes unbounded memory allocation and an out-of-memory termination of the Skipper process. The disrup
Remediation
References
Related Vulnerabilities
WordPress Plugin Nooz Cross-Site Scripting (1.6.0)
WordPress Plugin Forms:3rd-Party Inject Results Cross-Site Scripting (0.2)
Oracle HTTP Server CVE-2022-21375 Vulnerability (CVE-2022-21375)
WordPress Plugin Taxonomy Images Multiple Unspecified Vulnerabilities (0.6)
WordPress Plugin Contact Form DB-Elementor Cross-Site Scripting (1.7)