cbcvebase.
CVE-2019-11255
published 2019-12-05

CVE-2019-11255: Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshotter…

medium6.5CVSS 3.1
AVNACLPRHUINSUCHIHAN
Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshotter (<v0.4.2, <v1.0.2, v1.1, <1.2.2), and external-resizer (v0.1, v0.2) could result in unauthorized PersistentVolume data access or volume mutation during snapshot, restore from snapshot, cloning and resizing operations.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
github.comkubernetes-csi_external-provisioner>= 0 < 0.4.30.4.3
github.comkubernetes-csi_external-provisioner>= 1.0.0 < 1.0.21.0.2
github.comkubernetes-csi_external-provisioner>= 1.2.0 < 1.2.21.2.2
github.comkubernetes-csi_external-provisioner>= 1.3.0 < 1.3.11.3.1
github.comkubernetes-csi_external-snapshotter_v6>= 1.0.0 < 1.0.21.0.2
github.comkubernetes-csi_external-snapshotter_v6>= 1.2.0 < 1.2.21.2.2
kubernetesexternal-provisioner
kubernetesexternal-provisioner0.4.1 – 0.4.2
kubernetesexternal-provisioner1.0.0 – 1.0.1
kubernetesexternal-provisioner1.1.0 – 1.2.1
kubernetesexternal-resizer0.1.0 – 0.2.0
kubernetesexternal-snapshotter0.4.0 – 0.4.1
kubernetesexternal-snapshotter1.0.0 – 1.0.1
kubernetesexternal-snapshotter1.1.0 – 1.2.1
kuberneteskubernetes-csi_external-provisioner
kuberneteskubernetes-csi_external-provisioner
kuberneteskubernetes-csi_external-provisioner
kuberneteskubernetes-csi_external-provisioner
kuberneteskubernetes-csi_external-provisioner>= v1.14 < prior to 0.4.3prior to 0.4.3
kuberneteskubernetes-csi_external-resizer
kuberneteskubernetes-csi_external-resizer
kuberneteskubernetes-csi_external-snapshotter
kuberneteskubernetes-csi_external-snapshotter
kuberneteskubernetes-csi_external-snapshotter
kuberneteskubernetes-csi_external-snapshotter