CVE-2019-11255
Kubernetes CSI volume snapshot, cloning and resizing features can result in unauthorized volume data access or mutation
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshotter (<v0.4.2, <v1.0.2, v1.1, <1.2.2), and external-resizer (v0.1, v0.2) could result in unauthorized PersistentVolume data access or volume mutation during snapshot, restore from snapshot, cloning and resizing operations.
Una comprobación de entrada inapropiada en contenedores sidecar de Kubernetes CSI para external-provisioner (versiones anteriores a v0.4.3, versiones anteriores a v1.0.2, v1.1, versiones anteriores a v1.2.2, versiones anteriores a v1.3.1), external-snapshotter (versiones anteriores a v0.4.2, versiones anteriores a v1. 0.2, v1.1, versiones anteriores a 1.2.2) y external-resizer (versiones v0.1, v0.2), podrían resultar en el acceso no autorizado a los datos PersistentVolume o la mutación del volumen durante una imagen instantánea, una restauración desde una imagen instantánea, la clonación y el cambio de tamaño.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-04-17 CVE Reserved
- 2019-12-05 CVE Published
- 2024-03-09 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
https://github.com/kubernetes/kubernetes/issues/85233 | Mitigation | |
https://groups.google.com/forum/#%21topic/kubernetes-security-announce/aXiYN0q4uIw | Mailing List | |
https://security.netapp.com/advisory/ntap-20200810-0003 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHSA-2019:4054 | 2023-11-07 | |
https://access.redhat.com/errata/RHSA-2019:4096 | 2023-11-07 | |
https://access.redhat.com/errata/RHSA-2019:4099 | 2023-11-07 | |
https://access.redhat.com/errata/RHSA-2019:4225 | 2023-11-07 | |
https://access.redhat.com/security/cve/CVE-2019-11255 | 2019-12-17 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1772727 | 2019-12-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Kubernetes Search vendor "Kubernetes" | External-provisioner Search vendor "Kubernetes" for product "External-provisioner" | >= 0.4.1 <= 0.4.2 Search vendor "Kubernetes" for product "External-provisioner" and version " >= 0.4.1 <= 0.4.2" | - |
Affected
| ||||||
Kubernetes Search vendor "Kubernetes" | External-provisioner Search vendor "Kubernetes" for product "External-provisioner" | >= 1.0.0 <= 1.0.1 Search vendor "Kubernetes" for product "External-provisioner" and version " >= 1.0.0 <= 1.0.1" | - |
Affected
| ||||||
Kubernetes Search vendor "Kubernetes" | External-provisioner Search vendor "Kubernetes" for product "External-provisioner" | >= 1.1.0 <= 1.2.1 Search vendor "Kubernetes" for product "External-provisioner" and version " >= 1.1.0 <= 1.2.1" | - |
Affected
| ||||||
Kubernetes Search vendor "Kubernetes" | External-provisioner Search vendor "Kubernetes" for product "External-provisioner" | 1.3.0 Search vendor "Kubernetes" for product "External-provisioner" and version "1.3.0" | - |
Affected
| ||||||
Kubernetes Search vendor "Kubernetes" | External-resizer Search vendor "Kubernetes" for product "External-resizer" | >= 0.1.0 <= 0.2.0 Search vendor "Kubernetes" for product "External-resizer" and version " >= 0.1.0 <= 0.2.0" | - |
Affected
| ||||||
Kubernetes Search vendor "Kubernetes" | External-snapshotter Search vendor "Kubernetes" for product "External-snapshotter" | >= 0.4.0 <= 0.4.1 Search vendor "Kubernetes" for product "External-snapshotter" and version " >= 0.4.0 <= 0.4.1" | - |
Affected
| ||||||
Kubernetes Search vendor "Kubernetes" | External-snapshotter Search vendor "Kubernetes" for product "External-snapshotter" | >= 1.0.0 <= 1.0.1 Search vendor "Kubernetes" for product "External-snapshotter" and version " >= 1.0.0 <= 1.0.1" | - |
Affected
| ||||||
Kubernetes Search vendor "Kubernetes" | External-snapshotter Search vendor "Kubernetes" for product "External-snapshotter" | >= 1.1.0 <= 1.2.1 Search vendor "Kubernetes" for product "External-snapshotter" and version " >= 1.1.0 <= 1.2.1" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Openshift Container Platform Search vendor "Redhat" for product "Openshift Container Platform" | 3.11 Search vendor "Redhat" for product "Openshift Container Platform" and version "3.11" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Openshift Container Platform Search vendor "Redhat" for product "Openshift Container Platform" | 4.1 Search vendor "Redhat" for product "Openshift Container Platform" and version "4.1" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Openshift Container Platform Search vendor "Redhat" for product "Openshift Container Platform" | 4.2 Search vendor "Redhat" for product "Openshift Container Platform" and version "4.2" | - |
Affected
|