6.5
CVE-2019-11255
- EPSS 0.86%
- Published 05.12.2019 16:15:10
- Last modified 21.11.2024 04:20:48
- Source jordan@liggitt.net
- Teams watchlist Login
- Open Login
Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshotter (<v0.4.2, <v1.0.2, v1.1, <1.2.2), and external-resizer (v0.1, v0.2) could result in unauthorized PersistentVolume data access or volume mutation during snapshot, restore from snapshot, cloning and resizing operations.
Data is provided by the National Vulnerability Database (NVD)
Kubernetes ≫ External-provisioner Version >= 0.4.1 <= 0.4.2
Kubernetes ≫ External-provisioner Version >= 1.0.0 <= 1.0.1
Kubernetes ≫ External-provisioner Version >= 1.1.0 <= 1.2.1
Kubernetes ≫ External-provisioner Version1.3.0
Kubernetes ≫ External-resizer Version >= 0.1.0 <= 0.2.0
Kubernetes ≫ External-snapshotter Version >= 0.4.0 <= 0.4.1
Kubernetes ≫ External-snapshotter Version >= 1.0.0 <= 1.0.1
Kubernetes ≫ External-snapshotter Version >= 1.1.0 <= 1.2.1
Redhat ≫ Openshift Container Platform Version3.11
Redhat ≫ Openshift Container Platform Version4.1
Redhat ≫ Openshift Container Platform Version4.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.86% | 0.741 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.5 | 1.2 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
|
nvd@nist.gov | 5.5 | 8 | 4.9 |
AV:N/AC:L/Au:S/C:P/I:P/A:N
|
jordan@liggitt.net | 4.8 | 0.5 | 4.2 |
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:N
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.