Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshotter (<v0.4.2, <v1.0.2, v1.1, <1.2.2), and external-resizer (v0.1, v0.2) could result in unauthorized PersistentVolume data access or volume mutation during snapshot, restore from snapshot, cloning and resizing operations.
2019-12-05T16:15:10.567
2024-11-21T04:20:48.960
Modified
CVSSv3.1: 4.8 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:P/A:N
8.0
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | kubernetes | external-provisioner | ≤ 0.4.2 | Yes |
Application | kubernetes | external-provisioner | ≤ 1.0.1 | Yes |
Application | kubernetes | external-provisioner | ≤ 1.2.1 | Yes |
Application | kubernetes | external-provisioner | 1.3.0 | Yes |
Application | kubernetes | external-resizer | ≤ 0.2.0 | Yes |
Application | kubernetes | external-snapshotter | ≤ 0.4.1 | Yes |
Application | kubernetes | external-snapshotter | ≤ 1.0.1 | Yes |
Application | kubernetes | external-snapshotter | ≤ 1.2.1 | Yes |
Application | redhat | openshift_container_platform | 3.11 | Yes |
Application | redhat | openshift_container_platform | 4.1 | Yes |
Application | redhat | openshift_container_platform | 4.2 | Yes |