When parsing a JSON payload with deeply nested JSON structures, the parser in Apache Mesos versions pre-1.4.x, 1.4.0 to 1.4.2, 1.5.0 to 1.5.1, 1.6.0 to 1.6.1, and 1.7.0 might overflow the stack due to unbounded recursion. A malicious actor can therefore cause a denial of service of Mesos masters rendering the Mesos-controlled cluster inoperable.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-0387 When parsing a JSON payload with deeply nested JSON structures, the parser in Apache Mesos versions pre-1.4.x, 1.4.0 to 1.4.2, 1.5.0 to 1.5.1, 1.6.0 to 1.6.1, and 1.7.0 might overflow the stack due to unbounded recursion. A malicious actor can therefore cause a denial of service of Mesos masters rendering the Mesos-controlled cluster inoperable.
Github GHSA Github GHSA GHSA-p2xq-vcm7-xjj6 Stack Overflow in Apache Mesos
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-09-16T16:27:53.700Z

Reserved: 2018-06-05T00:00:00

Link: CVE-2018-11793

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-03-05T21:29:00.243

Modified: 2024-11-21T03:44:02.940

Link: CVE-2018-11793

cve-icon Redhat

Severity : Moderate

Publid Date: 2019-03-04T00:00:00Z

Links: CVE-2018-11793 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses