Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-6437

Опубликовано: 17 апр. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) before v3.0.1 allows remote authenticated users with PersistentVolume creation permissions to inject arbitrary mount options via comma injection. To remediate this issue, users should upgrade to version v3.0.1

A flaw was found in the AWS EFS CSI Driver. Remote authenticated users with PersistentVolume creation permissions can exploit an improper neutralization of argument delimiters by injecting commas into volume handling arguments. This allows for the injection of arbitrary mount options, which could lead to unauthorized access or modification of data.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4openshift4/ose-aws-efs-csi-driver-container-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-88
https://bugzilla.redhat.com/show_bug.cgi?id=2459243github.com/kubernetes-sigs/aws-efs-csi-driver: AWS EFS CSI Driver: Arbitrary mount option injection

EPSS

Процентиль: 35%
0.00424
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
4 месяца назад

Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) before v3.0.1 allows remote authenticated users with PersistentVolume creation permissions to inject arbitrary mount options via comma injection. To remediate this issue, users should upgrade to version v3.0.1

CVSS3: 6.5
github
4 месяца назад

Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields

EPSS

Процентиль: 35%
0.00424
Низкий

6.5 Medium

CVSS3

Уязвимость CVE-2026-6437