CVE-2024-0793: Red Hat Openshift Container Platform 4

High severity, CVSS 7.7. EPSS: 0.6% chance of exploitation in the next 30 days.

A flaw was found in kube-controller-manager. This issue occurs when the initial application of a HPA config YAML lacking a .spec.behavior.scaleUp block causes a denial of service due to KCM pods going into restart churn.

Affected products

  • Red Hat Red Hat Openshift Container Platform 4
  • Red Hat Red Hat Openshift Container Platform 4.12: before 0:4.12.0-202403042037.p0.g9946c63.assembly.stream.el9 (fixed in 0:4.12.0-202403042037.p0.g9946c63.assembly.stream.el9)

Published 2024-11-17. Last modified 2026-06-17.