← Back

CVE-2019-11255

nvd nist
Published: Dec 5, 2019Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Exploitability: 1.2 / Impact: 5.2
Source: NVD

Description

Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshotter (<v0.4.2, <v1.0.2, v1.1, <1.2.2), and external-resizer (v0.1, v0.2) could result in unauthorized PersistentVolume data access or volume mutation during snapshot, restore from snapshot, cloning and resizing operations.

Affected (11)

3 products
External Provisioner
External Resizer
External Snapshotter
1 product
Openshift Container Platform
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Kubernetes
From 0.4.1 to 0.4.2
From 1.0.0 to 1.0.1
From 1.1.0 to 1.2.1
Version 1.3.0
From 0.1.0 to 0.2.0
Kubernetes
From 0.4.0 to 0.4.1
From 1.0.0 to 1.0.1
From 1.1.0 to 1.2.1
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 3.11
Version 4.1
Version 4.2

References (14)

Source: jordan@liggitt.net
Third Party Advisory
Source: jordan@liggitt.net
Third Party Advisory
Source: jordan@liggitt.net
Third Party Advisory
Source: jordan@liggitt.net
Third Party Advisory
Source: jordan@liggitt.net
MitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.