CVE-2018-11793

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
05/03/2019
Last modified:
07/11/2023

Description

When parsing a JSON payload with deeply nested JSON structures, the parser in Apache Mesos versions pre-1.4.x, 1.4.0 to 1.4.2, 1.5.0 to 1.5.1, 1.6.0 to 1.6.1, and 1.7.0 might overflow the stack due to unbounded recursion. A malicious actor can therefore cause a denial of service of Mesos masters rendering the Mesos-controlled cluster inoperable.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:mesos:*:*:*:*:*:*:*:* 1.4.0 (including) 1.4.3 (excluding)
cpe:2.3:a:apache:mesos:*:*:*:*:*:*:*:* 1.5.0 (including) 1.5.2 (excluding)
cpe:2.3:a:apache:mesos:*:*:*:*:*:*:*:* 1.6.0 (including) 1.6.2 (excluding)
cpe:2.3:a:apache:mesos:*:*:*:*:*:*:*:* 1.7.0 (including) 1.7.1 (excluding)
cpe:2.3:a:apache:mesos:1.4.0:rc1:*:*:*:*:*:*
cpe:2.3:a:apache:mesos:1.4.0:rc2:*:*:*:*:*:*
cpe:2.3:a:apache:mesos:1.4.0:rc3:*:*:*:*:*:*
cpe:2.3:a:apache:mesos:1.4.0:rc4:*:*:*:*:*:*
cpe:2.3:a:apache:mesos:1.4.0:rc5:*:*:*:*:*:*
cpe:2.3:a:apache:mesos:1.8.0:dev:*:*:*:*:*:*