GHSA-f4w6-3rh6-6q4q
Kubernetes CSI Sidecar Containers Can Allow Unauthorized Data Access
Quick fix
GHSA-f4w6-3rh6-6q4q — github.com/kubernetes-csi/external-provisioner: upgrade to the fixed version with the command below.
go get github.com/kubernetes-csi/external-provisioner@v0.4.3Details
Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshotter (<v0.4.2, <v1.0.2, v1.1, <1.2.2), and external-resizer (v0.1, v0.2) could result in unauthorized PersistentVolume data access or volume mutation during snapshot, restore from snapshot, cloning and resizing operations.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 0.4.3go get github.com/kubernetes-csi/external-provisioner@v0.4.31.0.0Fixed in: 1.0.2go get github.com/kubernetes-csi/external-provisioner@v1.0.2No fixed version published yet for github.com/kubernetes-csi/external-provisioner (go modules). Pin to a known-safe version or switch to an alternative.
1.2.0Fixed in: 1.2.2go get github.com/kubernetes-csi/external-provisioner@v1.2.21.3.0Fixed in: 1.3.1go get github.com/kubernetes-csi/external-provisioner@v1.3.11.0.0Fixed in: 1.0.2go get github.com/kubernetes-csi/external-snapshotter/v6@v1.0.2No fixed version published yet for github.com/kubernetes-csi/external-snapshotter/v6 (go modules). Pin to a known-safe version or switch to an alternative.
1.2.0Fixed in: 1.2.2go get github.com/kubernetes-csi/external-snapshotter/v6@v1.2.2No fixed version published yet for github.com/kubernetes-csi/external-resizer (go modules). Pin to a known-safe version or switch to an alternative.
No fixed version published yet for github.com/kubernetes-csi/external-resizer (go modules). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2019-11255[ADVISORY]
- https://github.com/kubernetes/kubernetes/issues/85233[WEB]
- https://access.redhat.com/errata/RHSA-2019:4054[WEB]
- https://access.redhat.com/errata/RHSA-2019:4096[WEB]
- https://access.redhat.com/errata/RHSA-2019:4099[WEB]
- https://access.redhat.com/errata/RHSA-2019:4225[WEB]
- https://groups.google.com/forum/#!topic/kubernetes-security-announce/aXiYN0q4uIw[WEB]
- https://security.netapp.com/advisory/ntap-20200810-0003[WEB]