CVE-2022-31079 is a denial-of-service (DoS) vulnerability affecting KubeEdge versions prior to 1.11.1, 1.10.2, and 1.9.4. An authenticated attacker can exploit this by sending an oversized message to the Cloud Stream or Edge Stream servers, causing them to exhaust memory. This leads to a DoS for both CloudCore and EdgeCore components, with a CVSS score of 6.5 (Medium). While no active exploits or public exploit code are known, and community discussion is minimal, affected organizations should update KubeEdge or disable the cloudStream and edgeStream modules as a workaround.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.9.4CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:kubeedge:*:*:*:*:*:*:*:* | ||
>= 1.10.0, < 1.10.2CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:kubeedge:*:*:*:*:*:*:*:* | ||
>= 1.11.0, < 1.11.1CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:kubeedge:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.