CVE-2024-50311

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/10/2024
Last modified:
25/02/2025

Description

A denial of service (DoS) vulnerability was found in OpenShift. This flaw allows attackers to exploit the GraphQL batching functionality. The vulnerability arises when multiple queries can be sent within a single request, enabling an attacker to submit a request containing thousands of aliases in one query. This issue causes excessive resource consumption, leading to application unavailability for legitimate users.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*