In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsThere is no fixed version for github.com/openshift/hive/pkg/controller/hibernation
.
Affected versions of this package are vulnerable to Improper Check for Unusual or Exceptional Conditions due interaction between unexpected parameter values set for ClusterDeployment.hive.openshift.io/v1
and ClusterSync.hiveinternal.openshift.io/v1alpha1
objects in the Reconcile()
method in hibernation_controller.go
. An attacker can trigger a reconciliation loop and panic when spec.installed
is set to true, spec.hibernateAfter
is positive, and a nonexistent field is accessed.