OpenShift Hive Has an Uncontrolled Resource Consumption Vulnerability
        
  Moderate severity
        
          GitHub Reviewed
      
        Published
          Mar 19, 2025 
          to the GitHub Advisory Database
          •
          Updated Mar 20, 2025 
      
  
Package
Affected versions
<= 1.1.16
  Patched versions
None
  Description
        Published by the National Vulnerability Database
      Mar 19, 2025 
    
  
        Published to the GitHub Advisory Database
      Mar 19, 2025 
    
  
        Reviewed
      Mar 20, 2025 
    
  
        Last updated
      Mar 20, 2025 
    
  
A flaw was found in the Hive hibernation controller component of OpenShift Dedicated. The ClusterDeployment.hive.openshift.io/v1 resource can be created with the spec.installed field set to true, regardless of the installation status, and a positive timespan for the spec.hibernateAfter value. If a ClusterSync.hiveinternal.openshift.io/v1alpha1 resource is also created, the hive hibernation controller will enter the reconciliation loop leading to a panic when accessing a non-existing field in the ClusterDeployment’s status section, resulting in a denial of service.
References