A flaw was found in OpenShift Container Platform. Completed pods with restartPolicy: Never do not count toward ResourceQuota pod limits, and Kubernetes events are not quota-scoped. A non-privileged user who can create pods in a namespace can exploit this to generate a large volume of events that accumulate in etcd, causing API server performance degradation across the cluster.
| Vendor | Product | Versions |
|---|---|---|
| red hat | openshift container | — |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| red hat | openshift | cert_advisory | 90% |
Updated severity to HIGH, marked exploit as available, and added Denial of Service tag.
Updated description with new details, added affected version 4, changed severity to HIGH, and noted that no exploit is available.
Initial creation