First published: Thu Nov 14 2019(Updated: )
A security issue has been found in the kubernetes-csi external-provisioner, external-snapshotter, and external-resizer sidecars that impacts most versions of the sidecars bundled in Container Storage Interface (CSI) drivers. The vulnerabilities are medium severity and can result in unauthorized volume data access or mutation when using CSI volume snapshot, cloning or resizing features in Kubernetes. Upgrading your CSI drivers to the fixed sidecars is recommended. Upstream Issue: <a href="https://github.com/kubernetes/kubernetes/issues/85233">https://github.com/kubernetes/kubernetes/issues/85233</a> External Reference: <a href="https://groups.google.com/forum/#!topic/kubernetes-security-announce/aXiYN0q4uIw">https://groups.google.com/forum/#!topic/kubernetes-security-announce/aXiYN0q4uIw</a>
Credit: jordan@liggitt.net jordan@liggitt.net
Affected Software | Affected Version | How to fix |
---|---|---|
Kubernetes External-provisioner | >=0.4.1<=0.4.2 | |
Kubernetes External-provisioner | >=1.0.0<=1.0.1 | |
Kubernetes External-provisioner | >=1.1.0<=1.2.1 | |
Kubernetes External-provisioner | =1.3.0 | |
Kubernetes External-resizer | >=0.1.0<=0.2.0 | |
Kubernetes External-snapshotter | >=0.4.0<=0.4.1 | |
Kubernetes External-snapshotter | >=1.0.0<=1.0.1 | |
Kubernetes External-snapshotter | >=1.1.0<=1.2.1 | |
Redhat Openshift Container Platform | =3.11 | |
Redhat Openshift Container Platform | =4.1 | |
Redhat Openshift Container Platform | =4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11255 is a vulnerability that allows unauthorized access or volume mutation in Kubernetes CSI sidecar containers for external-provisioner, external-snapshotter, and external-resizer.
CVE-2019-11255 has a severity rating of 6.5, which is considered medium.
CVE-2019-11255 affects Kubernetes CSI sidecar containers for external-provisioner, external-snapshotter, and external-resizer, allowing unauthorized data access or volume mutation.
Versions <v0.4.3, <v1.0.2, v1.1, <v1.2.2, and <v1.3.1 of external-provisioner are affected by CVE-2019-11255.
To mitigate CVE-2019-11255, update external-provisioner, external-snapshotter, and external-resizer to the recommended versions.