PT-2019-4222 · Linux Foundation · Kubernetes

Xiangqian Yu

·

Published

2019-12-05

·

Updated

2022-05-24

·

CVE-2019-11255

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Kubernetes CSI sidecar containers for external-provisioner versions prior to 0.4.3, prior to 1.0.2, 1.1, prior to 1.2.2, prior to 1.3.1 Kubernetes CSI sidecar containers for external-snapshotter versions prior to 0.4.2, prior to 1.0.2, 1.1, prior to 1.2.2 Kubernetes CSI sidecar containers for external-resizer versions 0.1, 0.2
Description The issue is caused by improper input validation in Kubernetes CSI sidecar containers, which could result in unauthorized access to PersistentVolume data or volume mutation during operations such as snapshot, restore from snapshot, cloning, and resizing. This could allow a remote attacker to impact the confidentiality and integrity of protected information.
Recommendations For external-provisioner versions prior to 0.4.3, prior to 1.0.2, 1.1, prior to 1.2.2, prior to 1.3.1, update to a version that includes the fix for this issue. For external-snapshotter versions prior to 0.4.2, prior to 1.0.2, 1.1, prior to 1.2.2, update to a version that includes the fix for this issue. For external-resizer versions 0.1, 0.2, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the vulnerable CSI sidecar containers until a patch is available.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-04821
CVE-2019-11255
GHSA-F4W6-3RH6-6Q4Q
RHSA-2019:4054
RHSA-2019:4096
RHSA-2019:4225

Affected Products

Kubernetes