A security issue has been found in the kubernetes-csi external-provisioner, external-snapshotter, and external-resizer sidecars that impacts most versions of the sidecars bundled in Container Storage Interface (CSI) drivers. The vulnerabilities are medium severity and can result in unauthorized volume data access or mutation when using CSI volume snapshot, cloning or resizing features in Kubernetes. Upgrading your CSI drivers to the fixed sidecars is recommended.
Upstream Issue:
https://github.com/kubernetes/kubernetes/issues/85233
External Reference:
https://groups.google.com/forum/#!topic/kubernetes-security-announce/aXiYN0q4uIw