Input validation error in Kubernetes - CVE-2019-11255

 

Input validation error in Kubernetes - CVE-2019-11255

Published: December 11, 2019 / Updated: December 22, 2020


Vulnerability identifier: #VU23548
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-11255
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to insufficient validation of user-supplied input in Kubernetes CSI sidecar containers for external-provisioner (versions prior to 0.4.3 and 1.0.2, in version 1.1,  and versions prior to 1.2.2 and 1.3.1), external-snapshotter (versions prior to 0.4.2 and 1.0.2, in version 1.1, versions prior to 1.2.2), and external-resizer (versions 0.1,  and 0.2) . A local user can gain unauthorized PersistentVolume data access or volume mutation during snapshot, restore from snapshot, cloning and resizing operations.


Affected software

Kubernetes
Red Hat OpenShift Container Platform

How to mitigate CVE-2019-11255

Install update from vendor's website.

Red Hat OpenShift Container Platform - addressed in versions 4.1.27, 4.2.10

External References

Related Security Bulletins