A Allocation of Resources Without Limits or Throttling vulnerability in SUSE RKE2 allows attackers with access to K3s servers apiserver/supervisor port (TCP 6443) cause denial of service. This issue affects RKE2: from 1.24.0 before 1.24.17+rke2r1, from v1.25.0 before v1.25.13+rke2r1, from v1.26.0 before v1.26.8+rke2r1, from v1.27.0 before v1.27.5+rke2r1, from v1.28.0 before v1.28.1+rke2r1.
[
{
"events": [
{
"introduced": "1.24.0\\+rke2r1"
},
{
"fixed": "1.24.17\\+rke2r1"
}
]
},
{
"events": [
{
"introduced": "1.25.0\\+rke2r1"
},
{
"fixed": "1.25.13\\+rke2r1"
}
]
},
{
"events": [
{
"introduced": "1.26.0\\+rke2r1"
},
{
"fixed": "1.26.8\\+rke2r1"
}
]
},
{
"events": [
{
"introduced": "1.27.1\\+rke2r1"
},
{
"fixed": "1.27.5\\+rke2r1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.28.1+rke2r1-rc1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.28.1+rke2r1-rc2"
}
]
},
{
"events": [
{
"introduced": "1.24.0"
},
{
"fixed": "1.24.17+rke2r1"
}
]
},
{
"events": [
{
"introduced": "v1.25.0"
},
{
"fixed": "v1.25.13+rke2r1"
}
]
},
{
"events": [
{
"introduced": "v1.26.0"
},
{
"fixed": "v1.26.8+rke2r1"
}
]
},
{
"events": [
{
"introduced": "v1.27.0"
},
{
"fixed": "v1.27.5+rke2r1"
}
]
},
{
"events": [
{
"introduced": "v1.28.0"
},
{
"fixed": "v1.28.1+rke2r1"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-32186.json"