Intel

AIKIDO-2024-10230

k8s.io/autoscaler/vertical-pod-autoscaler is vulnerable to NULL Pointer Dereference

NULL Pointer Dereference Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Aug 27, 2024

10

Low Risk

This Affects:

gok8s.io/autoscaler/vertical-pod-autoscaler
1.2.0 - 1.2.0
Fixed in 1.2.1
Are you affected? Scan for Free

TL;DR

Affected versions of the package are vulnerable to null pointer dereference. A null pointer dereference typically causes the process to fail. Even with exception handling in place, it can be difficult to return the software to a safe operating state.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

k8s.io/autoscaler/vertical-pod-autoscaler is vulnerable to NULL Pointer Dereference in versions 1.2.0 - 1.2.0.

How to fix this

Upgrade the k8s.io/autoscaler/vertical-pod-autoscaler library to the patch version.