Kubernetes CSI volume snapshot, cloning and resizing features can result in unauthorized volume data access or mutation
Published Dec 5, 2019
6.5
MEDIUMCVSS 3.1
EPSS 2.01%
Description
Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshotter (<v0.4.2, <v1.0.2, v1.1, <1.2.2), and external-resizer (v0.1, v0.2) could result in unauthorized PersistentVolume data access or volume mutation during snapshot, restore from snapshot, cloning and resizing operations.
Affected products
-
- Version 1.1StatusaffectedConstraints-
- Version prior to 1.0.2StatusaffectedConstraints-
- Version prior to 1.2.2StatusaffectedConstraints-
- Version prior to 1.3.1StatusaffectedConstraints-
- Version v1.14StatusaffectedConstraints<prior to 0.4.3
- Version
-
- Version 0.1StatusaffectedConstraints-
- Version 0.2StatusaffectedConstraints-
- Version
-
- Version 1.1StatusaffectedConstraints-
- Version prior to 0.4.2StatusaffectedConstraints-
- Version prior to 1.0.2StatusaffectedConstraints-
- Version prior to 1.2.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Kubernetes | Kubernetes-Csi External-Provisioner | n/a |
| ||||||||||||||||||
| Kubernetes | Kubernetes-Csi External-Resizer | n/a |
| ||||||||||||||||||
| Kubernetes | Kubernetes-Csi External-Snapshotter | n/a |
|
Configuration 1
- ≥ 0.4.1 · ≤ 0.4.2
- ≥ 1.0.0 · ≤ 1.0.1
- ≥ 1.1.0 · ≤ 1.2.1
- 1.3.0
- ≥ 0.1.0 · ≤ 0.2.0
- ≥ 0.4.0 · ≤ 0.4.1
- ≥ 1.0.0 · ≤ 1.0.1
- ≥ 1.1.0 · ≤ 1.2.1
Configuration 2
- 3.11
- 4.1
- 4.2
No data.
Red Hat OpenShift Container Platform 3.11
openshift-external-storage-0:0.0.2-10.gitd3c94f0.el7
Fixed · RHSA-2019:4054
Red Hat OpenShift Container Platform 4.1
openshift-external-storage-0:0.0.2-11.gitd3c94f0.el7
Fixed · RHSA-2019:4225
Red Hat OpenShift Container Platform 4.2
openshift-external-storage-0:0.0.2-11.gitd3c94f0.el7
Fixed · RHSA-2019:4096
Red Hat OpenShift Container Platform 4.2
openshift4/ose-csi-external-provisioner-rhel7:v4.2.10-201912022352
Fixed · RHSA-2019:4099
Red Hat OpenShift Container Platform 3.11
csi-provisioner
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 3.11 | openshift-external-storage-0:0.0.2-10.gitd3c94f0.el7 | Fixed | RHSA-2019:4054 |
| Red Hat OpenShift Container Platform 4.1 | openshift-external-storage-0:0.0.2-11.gitd3c94f0.el7 | Fixed | RHSA-2019:4225 |
| Red Hat OpenShift Container Platform 4.2 | openshift-external-storage-0:0.0.2-11.gitd3c94f0.el7 | Fixed | RHSA-2019:4096 |
| Red Hat OpenShift Container Platform 4.2 | openshift4/ose-csi-external-provisioner-rhel7:v4.2.10-201912022352 | Fixed | RHSA-2019:4099 |
| Red Hat OpenShift Container Platform 3.11 | csi-provisioner | Not affected | n/a |
github.com/kubernetes-csi/external-provisioner
Go
Introduced 0 Fixed 0.4.3github.com/kubernetes-csi/external-provisioner
Go
Introduced 1.0.0 Fixed 1.0.2github.com/kubernetes-csi/external-provisioner
Go
Introduced 1.2.0 Fixed 1.2.2github.com/kubernetes-csi/external-provisioner
Go
Introduced 1.3.0 Fixed 1.3.1github.com/kubernetes-csi/external-snapshotter/v6
Go
Introduced 1.0.0 Fixed 1.0.2github.com/kubernetes-csi/external-snapshotter/v6
Go
Introduced 1.2.0 Fixed 1.2.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/kubernetes-csi/external-provisioner | 0 | 0.4.3 |
| Go | github.com/kubernetes-csi/external-provisioner | 1.0.0 | 1.0.2 |
| Go | github.com/kubernetes-csi/external-provisioner | 1.2.0 | 1.2.2 |
| Go | github.com/kubernetes-csi/external-provisioner | 1.3.0 | 1.3.1 |
| Go | github.com/kubernetes-csi/external-snapshotter/v6 | 1.0.0 | 1.0.2 |
| Go | github.com/kubernetes-csi/external-snapshotter/v6 | 1.2.0 | 1.2.2 |
Remediation
Vendor solution
Kubernetes feature gates can be disabled and RBAC permissions revoked from impacted CSI drivers, following instructions in https://github.com/kubernetes/kubernetes/issues/85233
Red Hat statement
OpenShift Container Storage Interface (CSI) is a Technology Preview (TP) feature in OpenShift Container Platform before version 4.2. https://access.redhat.com/support/offerings/techpreview
References (13)
- https://access.redhat.com/errata/RHSA-2019:4054 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4096 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4099 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4225 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-11255 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1772727 Issue Tracking
- https://github.com/advisories/GHSA-f4w6-3rh6-6q4q Advisory
- https://github.com/kubernetes/kubernetes/issues/85233 x_refsource_CONFIRMMitigationThird Party Advisory
- https://groups.google.com/forum/#!topic/kubernetes-security-announce/aXiYN0q4uIw
- https://groups.google.com/forum/#%21topic/kubernetes-security-announce/aXiYN0q4uIw mailing-listx_refsource_MLIST
- https://nvd.nist.gov/vuln/detail/CVE-2019-11255
- https://security.netapp.com/advisory/ntap-20200810-0003/ x_refsource_CONFIRM
- https://www.cve.org/CVERecord?id=CVE-2019-11255
Change history (0)
No recorded changes yet.