CVE-2018-1330

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
13/09/2018
Last modified:
07/11/2023

Description

When parsing a malformed JSON payload, libprocess in Apache Mesos versions 1.4.0 to 1.5.0 might crash due to an uncaught exception. Parsing chunked HTTP requests with trailers can lead to a libprocess crash too because of the mistakenly planted assertion. A malicious actor can therefore cause a denial of service of Mesos masters rendering the Mesos-controlled cluster inoperable.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:mesos:*:*:*:*:*:*:*:* 1.4.0 (including) 1.4.2 (excluding)
cpe:2.3:a:apache:mesos:*:*:*:*:*:*:*:* 1.5.0 (including) 1.5.1 (excluding)
cpe:2.3:a:apache:mesos:1.4.0:rc1:*:*:*:*:*:*
cpe:2.3:a:apache:mesos:1.4.0:rc2:*:*:*:*:*:*
cpe:2.3:a:apache:mesos:1.4.0:rc3:*:*:*:*:*:*
cpe:2.3:a:apache:mesos:1.4.0:rc4:*:*:*:*:*:*
cpe:2.3:a:apache:mesos:1.4.0:rc5:*:*:*:*:*:*
cpe:2.3:a:apache:mesos:1.6.0:rc1:*:*:*:*:*:*