« Volver al listado

CVE-2019-11255

Estado: ModificadaMedia (6.5)—

Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshotter (<v0.4.2, <v1.0.2, v1.1, <1.2.2), and external-resizer (v0.1, v0.2) could result in unauthorized PersistentVolume data access or volume mutation during snapshot, restore from snapshot, cloning and resizing operations.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-11255",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "jordan@liggitt.net",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.8,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4.2,
        "exploitabilityScore": 0.5
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 1.2
      }
    ]
  },
  "affected": [
    {
      "source": "jordan@liggitt.net",
      "affectedData": [
        {
          "vendor": "Kubernetes",
          "product": "kubernetes-csi external-provisioner",
          "versions": [
            {
              "status": "affected",
              "version": "prior to 1.0.2"
            },
            {
              "status": "affected",
              "version": "1.1"
            },
            {
              "status": "affected",
              "version": "prior to 1.2.2"
            },
            {
              "status": "affected",
              "version": "prior to 1.3.1"
            },
            {
              "status": "affected",
              "version": "v1.14",
              "lessThan": "prior to 0.4.3",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Kubernetes",
          "product": "kubernetes-csi external-snapshotter",
          "versions": [
            {
              "status": "affected",
              "version": "prior to 0.4.2"
            },
            {
              "status": "affected",
              "version": "prior to 1.0.2"
            },
            {
              "status": "affected",
              "version": "1.1"
            },
            {
              "status": "affected",
              "version": "prior to 1.2.2"
            }
          ]
        },
        {
          "vendor": "Kubernetes",
          "product": "kubernetes-csi external-resizer",
          "versions": [
            {
              "status": "affected",
              "version": "0.1"
            },
            {
              "status": "affected",
              "version": "0.2"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-12-05T16:15:10.567",
  "references": [
    {
      "url": "https://access.redhat.com/errata/RHSA-2019:4054",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "jordan@liggitt.net"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2019:4096",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "jordan@liggitt.net"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2019:4099",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "jordan@liggitt.net"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2019:4225",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "jordan@liggitt.net"
    },
    {
      "url": "https://github.com/kubernetes/kubernetes/issues/85233",
      "tags": [
        "Mitigation",
        "Third Party Advisory"
      ],
      "source": "jordan@liggitt.net"
    },
    {
      "url": "https://groups.google.com/forum/#%21topic/kubernetes-security-announce/aXiYN0q4uIw",
      "source": "jordan@liggitt.net"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20200810-0003/",
      "source": "jordan@liggitt.net"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2019:4054",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2019:4096",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2019:4099",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2019:4225",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/kubernetes/kubernetes/issues/85233",
      "tags": [
        "Mitigation",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://groups.google.com/forum/#%21topic/kubernetes-security-announce/aXiYN0q4uIw",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20200810-0003/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "jordan@liggitt.net",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshotter (<v0.4.2, <v1.0.2, v1.1, <1.2.2), and external-resizer (v0.1, v0.2) could result in unauthorized PersistentVolume data access or volume mutation during snapshot, restore from snapshot, cloning and resizing operations."
    },
    {
      "lang": "es",
      "value": "Una comprobación de entrada inapropiada en contenedores sidecar de Kubernetes CSI para external-provisioner (versiones anteriores a v0.4.3, versiones anteriores a v1.0.2, v1.1, versiones anteriores a v1.2.2, versiones anteriores a v1.3.1), external-snapshotter (versiones anteriores a v0.4.2, versiones anteriores a v1. 0.2, v1.1, versiones anteriores a 1.2.2) y external-resizer (versiones v0.1, v0.2), podrían resultar en el acceso no autorizado a los datos PersistentVolume o la mutación del volumen durante una imagen instantánea, una restauración desde una imagen instantánea, la clonación y el cambio de tamaño."
    }
  ],
  "lastModified": "2026-06-17T02:12:38.040",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:kubernetes:external-provisioner:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9A78A50B-5286-400D-A54A-49F1023D97D6",
              "versionEndIncluding": "0.4.2",
              "versionStartIncluding": "0.4.1"
            },
            {
              "criteria": "cpe:2.3:a:kubernetes:external-provisioner:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A5CDEBDE-A093-4D75-A289-7F8D8F47C163",
              "versionEndIncluding": "1.0.1",
              "versionStartIncluding": "1.0.0"
            },
            {
              "criteria": "cpe:2.3:a:kubernetes:external-provisioner:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8CD30FBE-792A-42E3-9FAA-3122EBBEFC4C",
              "versionEndIncluding": "1.2.1",
              "versionStartIncluding": "1.1.0"
            },
            {
              "criteria": "cpe:2.3:a:kubernetes:external-provisioner:1.3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "686C1D64-DB77-451E-A3EC-9A415F7EAA2B"
            },
            {
              "criteria": "cpe:2.3:a:kubernetes:external-resizer:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "920BC20F-8C59-4A34-AA0C-EBFD469C59C3",
              "versionEndIncluding": "0.2.0",
              "versionStartIncluding": "0.1.0"
            },
            {
              "criteria": "cpe:2.3:a:kubernetes:external-snapshotter:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B2DDFBDD-3AA1-40E4-B349-90D40C6E70F9",
              "versionEndIncluding": "0.4.1",
              "versionStartIncluding": "0.4.0"
            },
            {
              "criteria": "cpe:2.3:a:kubernetes:external-snapshotter:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F14DDAA3-4DD3-43D9-B934-4856C9A6B138",
              "versionEndIncluding": "1.0.1",
              "versionStartIncluding": "1.0.0"
            },
            {
              "criteria": "cpe:2.3:a:kubernetes:external-snapshotter:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0279E824-AF71-4EA1-8F41-3FAF256DC6EC",
              "versionEndIncluding": "1.2.1",
              "versionStartIncluding": "1.1.0"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2F87326E-0B56-4356-A889-73D026DB1D4B"
            },
            {
              "criteria": "cpe:2.3:a:redhat:openshift_container_platform:4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "064E7BDD-4EF0-4A0D-A38D-8C75BAFEDCEF"
            },
            {
              "criteria": "cpe:2.3:a:redhat:openshift_container_platform:4.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4C85A84D-A70F-4B02-9E5D-CD9660ABF048"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "jordan@liggitt.net"
}