Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshotter (<v0.4.2, <v1.0.2, v1.1, <1.2.2), and external-resizer (v0.1, v0.2) could result in unauthorized PersistentVolume data access or volume mutation during snapshot, restore from snapshot, cloning and resizing operations.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-3689 Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshotter (<v0.4.2, <v1.0.2, v1.1, <1.2.2), and external-resizer (v0.1, v0.2) could result in unauthorized PersistentVolume data access or volume mutation during snapshot, restore from snapshot, cloning and resizing operations.
Github GHSA Github GHSA GHSA-f4w6-3rh6-6q4q Kubernetes CSI Sidecar Containers Can Allow Unauthorized Data Access
Fixes

Solution

No solution given by the vendor.


Workaround

Kubernetes feature gates can be disabled and RBAC permissions revoked from impacted CSI drivers, following instructions in https://github.com/kubernetes/kubernetes/issues/85233

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: kubernetes

Published:

Updated: 2024-09-16T23:05:20.635Z

Reserved: 2019-04-17T00:00:00

Link: CVE-2019-11255

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-12-05T16:15:10.567

Modified: 2024-11-21T04:20:48.960

Link: CVE-2019-11255

cve-icon Redhat

Severity : Moderate

Publid Date: 2019-11-15T00:00:00Z

Links: CVE-2019-11255 - Bugzilla

cve-icon OpenCVE Enrichment

No data.