CVE-2019-11255: Kubernetes CSI volume snapshot, cloning and resizing features can result in unauthorized volume data access or mutation
A security issue has been found in the kubernetes-csi external-provisioner, external-snapshotter, and external-resizer sidecars that impacts most versions of the sidecars bundled in Container Storage Interface (CSI) drivers. The vulnerabilities are medium severity and can result in unauthorized volume data access or mutation when using CSI volume snapshot, cloning or resizing features in Kubernetes. Upgrading your CSI drivers to the fixed sidecars is recommended.
Upstream Issue:
https://github.com/kubernetes/kubernetes/issues/85233
External Reference:
https://groups.google.com/forum/#!topic/kubernetes-security-announce/aXiYN0q4uIw
Other sources
Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshotter (<v0.4.2, <v1.0.2, v1.1, <1.2.2), and external-resizer (v0.1, v0.2) could result in unauthorized PersistentVolume data access or volume mutation during snapshot, restore from snapshot, cloning and resizing operations.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-11255?
CVE-2019-11255 is a vulnerability that allows unauthorized access or volume mutation in Kubernetes CSI sidecar containers for external-provisioner, external-snapshotter, and external-resizer.
What is the severity of CVE-2019-11255?
CVE-2019-11255 has a severity rating of 6.5, which is considered medium.
How does CVE-2019-11255 affect Kubernetes CSI sidecar containers?
CVE-2019-11255 affects Kubernetes CSI sidecar containers for external-provisioner, external-snapshotter, and external-resizer, allowing unauthorized data access or volume mutation.
Which versions of external-provisioner are affected by CVE-2019-11255?
Versions <v0.4.3, <v1.0.2, v1.1, <v1.2.2, and <v1.3.1 of external-provisioner are affected by CVE-2019-11255.
What can I do to mitigate the vulnerability?
To mitigate CVE-2019-11255, update external-provisioner, external-snapshotter, and external-resizer to the recommended versions.