Back

MEDIUM

Kubernetes CSI volume snapshot, cloning and resizing features can result in unauthorized volume data access or mutation

Published Dec 5, 2019

Description

Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshotter (<v0.4.2, <v1.0.2, v1.1, <1.2.2), and external-resizer (v0.1, v0.2) could result in unauthorized PersistentVolume data access or volume mutation during snapshot, restore from snapshot, cloning and resizing operations.

Affected products

Remediation

Vendor solution

Kubernetes feature gates can be disabled and RBAC permissions revoked from impacted CSI drivers, following instructions in https://github.com/kubernetes/kubernetes/issues/85233

Red Hat statement

OpenShift Container Storage Interface (CSI) is a Technology Preview (TP) feature in OpenShift Container Platform before version 4.2. https://access.redhat.com/support/offerings/techpreview

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner kubernetes
Published Dec 5, 2019
Updated Sep 16, 2024
Reserved Apr 17, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Nov 15, 2019
GHSA-F4W6-3RH6-6Q4Q