GHSA-f4w6-3rh6-6q4q

    Dashboard / Vulnerabilities / GHSA-f4w6-3rh6-6q4q

    GHSA-f4w6-3rh6-6q4q

    Published: 24 May 2022Last Modified: 10 Sept 2026

    Summary: Kubernetes CSI Sidecar Containers Can Allow Unauthorized Data Access

    Details: Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshotter (<v0.4.2, <v1.0.2, v1.1, <1.2.2), and external-resizer (v0.1, v0.2) could result in unauthorized PersistentVolume data access or volume mutation during snapshot, restore from snapshot, cloning and resizing operations.

    Affected packages

    Package

    Name: github.com/kubernetes-csi/external-provisioner

    Purl: pkg:golang/github.com/kubernetes-csi/external-provisioner

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -0.4.3

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-f4w6-3rh6-6q4q | CVE-DB