Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hwrr-rhmm-vcvf

Опубликовано: 15 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

NULL Pointer Dereference in Kubernetes CSI snapshot-controller

Kubernetes CSI snapshot-controller prior to v2.1.3 and v3.0.2 could panic when processing a VolumeSnapshot custom resource when:

  • The VolumeSnapshot referenced a non-existing PersistentVolumeClaim and the VolumeSnapshot did not reference any VolumeSnapshotClass.
  • The snapshot-controller crashes, is automatically restarted by Kubernetes, and processes the same VolumeSnapshot custom resource after the restart, entering an endless crashloop.

Only the volume snapshot feature is affected by this vulnerability. When exploited, users can’t take snapshots of their volumes or delete the snapshots. All other Kubernetes functionality is not affected.

Пакеты

Наименование

github.com/kubernetes-csi/external-snapshotter/v2

go
Затронутые версииВерсия исправления

>= 2.0.0, < 2.1.3

2.1.3

Наименование

github.com/kubernetes-csi/external-snapshotter/v3

go
Затронутые версииВерсия исправления

>= 3.0.0, < 3.0.2

3.0.2

EPSS

Процентиль: 57%
0.00349
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-476

Связанные уязвимости

CVSS3: 5.3
redhat
больше 5 лет назад

Kubernetes CSI snapshot-controller prior to v2.1.3 and v3.0.2 could panic when processing a VolumeSnapshot custom resource when: - The VolumeSnapshot referenced a non-existing PersistentVolumeClaim and the VolumeSnapshot did not reference any VolumeSnapshotClass. - The snapshot-controller crashes, is automatically restarted by Kubernetes, and processes the same VolumeSnapshot custom resource after the restart, entering an endless crashloop. Only the volume snapshot feature is affected by this vulnerability. When exploited, users can’t take snapshots of their volumes or delete the snapshots. All other Kubernetes functionality is not affected.

CVSS3: 4.3
nvd
около 5 лет назад

Kubernetes CSI snapshot-controller prior to v2.1.3 and v3.0.2 could panic when processing a VolumeSnapshot custom resource when: - The VolumeSnapshot referenced a non-existing PersistentVolumeClaim and the VolumeSnapshot did not reference any VolumeSnapshotClass. - The snapshot-controller crashes, is automatically restarted by Kubernetes, and processes the same VolumeSnapshot custom resource after the restart, entering an endless crashloop. Only the volume snapshot feature is affected by this vulnerability. When exploited, users can’t take snapshots of their volumes or delete the snapshots. All other Kubernetes functionality is not affected.

EPSS

Процентиль: 57%
0.00349
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-476