A security issue has been found in the kubernetes-csi external-provisioner, external-snapshotter, and external-resizer sidecars that impacts most versions of the sidecars bundled in Container Storage Interface (CSI) drivers. The vulnerabilities are medium severity and can result in unauthorized volume data access or mutation when using CSI volume snapshot, cloning or resizing features in Kubernetes. Upgrading your CSI drivers to the fixed sidecars is recommended. Upstream Issue: https://github.com/kubernetes/kubernetes/issues/85233 External Reference: https://groups.google.com/forum/#!topic/kubernetes-security-announce/aXiYN0q4uIw
Statement: OpenShift Container Storage Interface (CSI) is a Technology Preview (TP) feature in OpenShift Container Platform before version 4.2. https://access.redhat.com/support/offerings/techpreview
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.2 Via RHSA-2019:4099 https://access.redhat.com/errata/RHSA-2019:4099
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2019-11255
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.2 Via RHSA-2019:4096 https://access.redhat.com/errata/RHSA-2019:4096
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 3.11 Via RHSA-2019:4054 https://access.redhat.com/errata/RHSA-2019:4054
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.1 Via RHSA-2019:4225 https://access.redhat.com/errata/RHSA-2019:4225