CVE-2019-11255

Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshotter (<v0.4.2, <v1.0.2, v1.1, <1.2.2), and external-resizer (v0.1, v0.2) could result in unauthorized PersistentVolume data access or volume mutation during snapshot, restore from snapshot, cloning and resizing operations.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.8 MEDIUM
NETWORK
HIGH
HIGH
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
kubernetesexternal-provisioner
0.4.1 ≤
𝑥
≤ 0.4.2
kubernetesexternal-provisioner
1.0.0 ≤
𝑥
≤ 1.0.1
kubernetesexternal-provisioner
1.1.0 ≤
𝑥
≤ 1.2.1
kubernetesexternal-provisioner
1.3.0
kubernetesexternal-resizer
0.1.0 ≤
𝑥
≤ 0.2.0
kubernetesexternal-snapshotter
0.4.0 ≤
𝑥
≤ 0.4.1
kubernetesexternal-snapshotter
1.0.0 ≤
𝑥
≤ 1.0.1
kubernetesexternal-snapshotter
1.1.0 ≤
𝑥
≤ 1.2.1
redhatopenshift_container_platform
3.11
redhatopenshift_container_platform
4.1
redhatopenshift_container_platform
4.2
𝑥
= Vulnerable software versions