CVE-2024-12401

A flaw was found in the cert-manager package. This flaw allows an attacker who can modify PEM data that the cert-manager reads, for example, in a Secret resource, to use large amounts of CPU in the cert-manager controller pod to effectively create a denial-of-service (DoS) vector for the cert-manager in the cluster.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) Se encontró una falla en el paquete cert-manager. Esta falla permite que un atacante que pueda modificar los datos PEM que lee el cert-manager, por ejemplo, en un recurso secreto, utilice grandes cantidades de CPU en el módulo controlador del cert-manager para crear efectivamente un vector de denegación de servicio (DoS) para el cert-manager en el clúster.

12 Dec 2024, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-12 09:15

Updated : 2026-04-15 00:35


NVD link : CVE-2024-12401

Mitre link : CVE-2024-12401

CVE.ORG link : CVE-2024-12401


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation