A flaw was found in the cert-manager package. This flaw allows an attacker who can modify PEM data that the cert-manager reads, for example, in a Secret resource, to use large amounts of CPU in the cert-manager controller pod to effectively create a denial-of-service (DoS) vector for the cert-manager in the cluster.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/12xxx/CVE-2024-12401.json",
"cna_assigner": "redhat",
"cwe_ids": [
"CWE-20"
]
}{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "1.12.14"
},
{
"introduced": "1.13.0-alpha.0"
},
{
"last_affected": "1.15.4"
},
{
"introduced": "1.16.0-alpha.0"
},
{
"last_affected": "1.16.2"
}
]
}