CVE-2024-0793 describes a denial-of-service vulnerability in kube-controller-manager (KCM) that occurs when a Horizontal Pod Autoscaler (HPA) configuration YAML is initially applied without a .spec.behavior.scaleUp block, causing KCM pods to repeatedly restart. This issue carries a CVSS score of 7.7 (HIGH), indicating a network-exploitable vulnerability with low attack complexity that can lead to high availability impact. Despite its severity, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4 | All Versions ImpactedCNA affecteddefault affected | |
| Red Hat | Red Hat OpenShift Container Platform 4.12 | Range not provided by sourceCNA affecteddefault affected | |
| Https://Github.Com/Kubernetes | Kube-Controller-Manager | >= 0, < 1.27CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.