CVE-2019-11255

medium

Description

Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshotter (<v0.4.2, <v1.0.2, v1.1, <1.2.2), and external-resizer (v0.1, v0.2) could result in unauthorized PersistentVolume data access or volume mutation during snapshot, restore from snapshot, cloning and resizing operations.

References

https://security.netapp.com/advisory/ntap-20200810-0003/

https://groups.google.com/forum/#%21topic/kubernetes-security-announce/aXiYN0q4uIw

https://github.com/kubernetes/kubernetes/issues/85233

https://access.redhat.com/errata/RHSA-2019:4225

https://access.redhat.com/errata/RHSA-2019:4099

https://access.redhat.com/errata/RHSA-2019:4096

https://access.redhat.com/errata/RHSA-2019:4054

Details

Source: Mitre, NVD

Published: 2019-12-05

Updated: 2023-11-07

Risk Information

CVSS v2

Base Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

Severity: Medium