Kubernetes CSI snapshot-controller DoS
Published Jan 21, 2021
6.5
MEDIUMCVSS 3.1
EPSS 2.27%
Description
Kubernetes CSI snapshot-controller prior to v2.1.3 and v3.0.2 could panic when processing a VolumeSnapshot custom resource when: - The VolumeSnapshot referenced a non-existing PersistentVolumeClaim and the VolumeSnapshot did not reference any VolumeSnapshotClass. - The snapshot-controller crashes, is automatically restarted by Kubernetes, and processes the same VolumeSnapshot custom resource after the restart, entering an endless crashloop. Only the volume snapshot feature is affected by this vulnerability. When exploited, users can’t take snapshots of their volumes or delete the snapshots. All other Kubernetes functionality is not affected.
Affected products
-
- Version snapshot-controller v2.1StatusaffectedConstraints<=v2.1.2
- Version snapshot-controller v3.0StatusaffectedConstraints<=v3.0.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Kubernetes | CSI Snapshotter | n/a |
|
- ≥ 2.1.0 · < 2.1.3
- ≥ 3.0.0 · < 3.0.2
No data.
Red Hat OpenShift Container Platform 4
openshift4/ose-csi-external-snapshotter
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-csi-external-snapshotter-rhel8
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-csi-snapshot-controller-rhel9
Not affected
Red Hat OpenShift Virtualization 2
hyperconverged-cluster-operator
Not affected
Red Hat OpenShift Virtualization 2
virt-cdi-controller
Not affected
Red Hat OpenShift Virtualization 2
virt-controller
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 4 | openshift4/ose-csi-external-snapshotter | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-csi-external-snapshotter-rhel8 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-csi-snapshot-controller-rhel9 | Not affected | n/a |
| Red Hat OpenShift Virtualization 2 | hyperconverged-cluster-operator | Not affected | n/a |
| Red Hat OpenShift Virtualization 2 | virt-cdi-controller | Not affected | n/a |
| Red Hat OpenShift Virtualization 2 | virt-controller | Not affected | n/a |
github.com/kubernetes-csi/external-snapshotter/v3
Go
Introduced 3.0.0 Fixed 3.0.2github.com/kubernetes-csi/external-snapshotter/v2
Go
Introduced 2.0.0 Fixed 2.1.3
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/kubernetes-csi/external-snapshotter/v3 | 3.0.0 | 3.0.2 |
| Go | github.com/kubernetes-csi/external-snapshotter/v2 | 2.0.0 | 2.1.3 |
Remediation
Vendor solution
Prior to upgrading, this vulnerability can be mitigated by restricting creation of VolumeSnapshot custom resources in API group snapshot.storage.k8s.io only to trusted users.
Red Hat statement
This vulnerability only affects versions v3.0.0 - v3.0.1 of the upstream snapshot-controller. No released component of OpenShift Container Platform (OCP) includes a vulnerable version. The first release of OCP 4.6 included v3 of a snapshot-controller with this fix, earlier versions of OCP include v2, which is not affected by this vulnerability. Similarly, no components of OpenShift Virtualization include a vulnerable version.
References (8)
- https://access.redhat.com/security/cve/CVE-2020-8569 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1897314 Issue Tracking
- https://github.com/advisories/GHSA-hwrr-rhmm-vcvf Advisory
- https://github.com/kubernetes-csi/external-snapshotter/issues/380 x_refsource_MISCExploitThird Party Advisory
- https://github.com/kubernetes-csi/external-snapshotter/issues/421
- https://groups.google.com/g/kubernetes-security-announce/c/1EzCr1qUxxU x_refsource_MISCMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-8569
- https://www.cve.org/CVERecord?id=CVE-2020-8569
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-8569 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1897314 | Issue Tracking | |
| https://github.com/advisories/GHSA-hwrr-rhmm-vcvf | Advisory | |
| https://github.com/kubernetes-csi/external-snapshotter/issues/380 | x_refsource_MISCExploitThird Party Advisory | |
| https://github.com/kubernetes-csi/external-snapshotter/issues/421 | ||
| https://groups.google.com/g/kubernetes-security-announce/c/1EzCr1qUxxU | x_refsource_MISCMailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-8569 | ||
| https://www.cve.org/CVERecord?id=CVE-2020-8569 |
Change history (0)
No recorded changes yet.