GHSA-f4p5-x4vc-mh4v
MEDIUMCVE-2022-39272Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields .spec.interval or .spec.timeout (and structured variations of these fields), causing the entire object type to stop being processed.
- Affected
- >=0.0.2, <0.29.0
- Fixed in
- 0.30.0
- Published
- 2022-10-19
- Source
- github