PT-2022-20512 · Kubeedge · Kubeedge

Adam Korczynski

+1

·

Published

2022-06-25

·

Updated

2024-08-21

·

CVE-2022-31077

CVSS v3.1

4.0

Medium

VectorAV:A/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions KubeEdge versions prior to 1.11.0 KubeEdge versions prior to 1.10.1 KubeEdge versions prior to 1.9.3
Description A malicious message response from KubeEdge can crash the CSI Driver controller server by triggering a nil-pointer dereference panic, resulting in a denial of service. This issue affects KubeEdge, which extends native containerized application orchestration and device management to hosts at the Edge. An attacker would need to be an authenticated user of the Cloud and launch the csidriver to potentially exploit this issue.
Recommendations For versions prior to 1.11.0, update to version 1.11.0 to resolve the issue. For versions prior to 1.10.1, update to version 1.10.1 to resolve the issue. For versions prior to 1.9.3, update to version 1.9.3 to resolve the issue. As a temporary workaround, consider restricting access to the CSI Driver controller server until a patch is applied. At the moment, there are no other workarounds available.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-31077
GHSA-X938-FVFW-7JH5
GO-2022-0501

Affected Products

Kubeedge