Impact
Improper neutralization of argument delimiters in the volume handling component of AWS EFS CSI Driver allows authenticated users who can create PersistentVolumes to inject arbitrary mount options via the comma‑separated mounttargetipmap attribute. This flaw can lead to unauthorized changes to EFS mount behavior, potentially enabling a malicious user to mount EFS volumes with unexpected options that could expose sensitive data, bypass security controls, or disrupt storage access.
Affected Systems
AWS EFS CSI Driver – v3.1.0 through v3.4.2 – is affected. The component resides in the volume handling logic used by Kubernetes clusters that integrate with AWS EFS. Users deploying the driver in these versions are at risk.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. Because the exploit requires authenticated users with PersistentVolume creation permissions, the attack vector is remote, authenticated, with limited scope to cluster administrators. EPSS is not available, but the vulnerability is not listed in CISA KEV. The impact is limited to mount option manipulation; however, privileged users could leverage this to bypass storage safeguards or cause denial of service within the cluster.
OpenCVE Enrichment