Bug 1772727 (CVE-2019-11255) - CVE-2019-11255 kubernetes-csi: CSI volume snapshot, cloning and resizing features can result in unauthorized volume data access or mutation
Summary: CVE-2019-11255 kubernetes-csi: CSI volume snapshot, cloning and resizing feat...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2019-11255
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1774304 1774305 1774306 1774307 1774310 1779024
Blocks: 1772728
TreeView+ depends on / blocked
 
Reported: 2019-11-15 01:33 UTC by Sam Fowler
Modified: 2021-02-16 21:03 UTC (History)
9 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2019-12-11 07:24:01 UTC


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2019:4054 0 None None None 2019-12-16 13:55:52 UTC
Red Hat Product Errata RHSA-2019:4096 0 None None None 2019-12-11 08:39:14 UTC
Red Hat Product Errata RHSA-2019:4099 0 None None None 2019-12-11 04:54:20 UTC
Red Hat Product Errata RHSA-2019:4225 0 None None None 2019-12-17 02:18:10 UTC

Description Sam Fowler 2019-11-15 01:33:58 UTC
A security issue has been found in the kubernetes-csi external-provisioner, external-snapshotter, and external-resizer sidecars that impacts most versions of the sidecars bundled in Container Storage Interface (CSI) drivers. The vulnerabilities are medium severity and can result in unauthorized volume data access or mutation when using CSI volume snapshot, cloning or resizing features in Kubernetes. Upgrading your CSI drivers to the fixed sidecars is recommended.


Upstream Issue:

https://github.com/kubernetes/kubernetes/issues/85233


External Reference:

https://groups.google.com/forum/#!topic/kubernetes-security-announce/aXiYN0q4uIw

Comment 3 Sam Fowler 2019-11-20 05:32:56 UTC
Statement:

OpenShift Container Storage Interface (CSI) is a Technology Preview (TP) feature in OpenShift Container Platform before version 4.2.

https://access.redhat.com/support/offerings/techpreview

Comment 7 errata-xmlrpc 2019-12-11 04:54:19 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.2

Via RHSA-2019:4099 https://access.redhat.com/errata/RHSA-2019:4099

Comment 8 Product Security DevOps Team 2019-12-11 07:24:01 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2019-11255

Comment 9 errata-xmlrpc 2019-12-11 08:39:12 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.2

Via RHSA-2019:4096 https://access.redhat.com/errata/RHSA-2019:4096

Comment 11 errata-xmlrpc 2019-12-16 13:55:50 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 3.11

Via RHSA-2019:4054 https://access.redhat.com/errata/RHSA-2019:4054

Comment 12 errata-xmlrpc 2019-12-17 02:18:08 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.1

Via RHSA-2019:4225 https://access.redhat.com/errata/RHSA-2019:4225


Note You need to log in before you can comment on or make changes to this bug.