{"id":"CVE-2019-11255","aliases":["GHSA-f4w6-3rh6-6q4q"],"url":"https://o3.security/vulnerability/CVE-2019-11255","summary":"Kubernetes CSI Sidecar Containers Can Allow Unauthorized Data Access","details":"Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshotter (<v0.4.2, <v1.0.2, v1.1, <1.2.2), and external-resizer (v0.1, v0.2) could result in unauthorized PersistentVolume data access or volume mutation during snapshot, restore from snapshot, cloning and resizing operations.","published":"2019-12-05T16:15:10.567Z","modified":"2026-07-08T05:57:45.136807176Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N"},"epss":{"score":0.01764,"percentile":0.75819,"asOf":"2026-07-31"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/kubernetes-csi/external-provisioner","fixedVersion":"0.4.3"},{"ecosystem":"Go","name":"github.com/kubernetes-csi/external-provisioner","fixedVersion":"1.0.2"},{"ecosystem":"Go","name":"github.com/kubernetes-csi/external-provisioner","fixedVersion":null},{"ecosystem":"Go","name":"github.com/kubernetes-csi/external-provisioner","fixedVersion":"1.2.2"},{"ecosystem":"Go","name":"github.com/kubernetes-csi/external-provisioner","fixedVersion":"1.3.1"},{"ecosystem":"Go","name":"github.com/kubernetes-csi/external-snapshotter/v6","fixedVersion":"1.0.2"},{"ecosystem":"Go","name":"github.com/kubernetes-csi/external-snapshotter/v6","fixedVersion":null},{"ecosystem":"Go","name":"github.com/kubernetes-csi/external-snapshotter/v6","fixedVersion":"1.2.2"},{"ecosystem":"Go","name":"github.com/kubernetes-csi/external-resizer","fixedVersion":null},{"ecosystem":"Go","name":"github.com/kubernetes-csi/external-resizer","fixedVersion":null}],"fix":null,"references":[{"type":"WEB","url":"https://groups.google.com/forum/#%21topic/kubernetes-security-announce/aXiYN0q4uIw"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:4054"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:4096"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:4099"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:4225"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20200810-0003/"},{"type":"REPORT","url":"https://github.com/kubernetes/kubernetes/issues/85233"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:57:45.136807176Z"}}