Description
When parsing a malformed JSON payload, libprocess in Apache Mesos versions 1.4.0 to 1.5.0 might crash due to an uncaught exception. Parsing chunked HTTP requests with trailers can lead to a libprocess crash too because of the mistakenly planted assertion. A malicious actor can therefore cause a denial of service of Mesos masters rendering the Mesos-controlled cluster inoperable.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-3293 | When parsing a malformed JSON payload, libprocess in Apache Mesos versions 1.4.0 to 1.5.0 might crash due to an uncaught exception. Parsing chunked HTTP requests with trailers can lead to a libprocess crash too because of the mistakenly planted assertion. A malicious actor can therefore cause a denial of service of Mesos masters rendering the Mesos-controlled cluster inoperable. |
Github GHSA |
GHSA-95q3-pppp-r683 | Crash when decoding malformed HTTP requests or malformed JSON payload |
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-09-16T20:42:57.117Z
Reserved: 2017-12-07T00:00:00.000Z
Link: CVE-2018-1330
No data.
Status : Modified
Published: 2018-09-13T19:29:00.400
Modified: 2024-11-21T03:59:38.273
Link: CVE-2018-1330
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA