Impact
An authenticated Kubernetes user with PersistentVolume creation privileges can exploit an unverified ownership flaw in the Amazon EFS CSI Driver to pair an access point from one EFS filesystem with a different target filesystem. This allows recursive deletion of directories on a filesystem that the user is not authorized to modify, resulting in loss of data and potential service disruption. The weakness is a broken access control flaw (CWE-283).
Affected Systems
Amazon Web Services' AWS EFS CSI Driver, any installed version prior to v3.4.1. The vulnerability affects the volume deletion component, so all clusters running earlier releases of the driver are impacted.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate severity vulnerability. Exploitation requires an authenticated Kubernetes account with permissions to create PersistentVolumes; such permissions are often granted within cluster service accounts or developers. Because the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the likelihood of exploitation is uncertain but possible in environments where privileged K8s users are compromised or misconfigured. No additional exploitation prerequisites are disclosed in the CVE description beyond the stated privileges.
OpenCVE Enrichment