CVE-2019-11255: Kubernetes External-Provisioner

Medium severity, CVSS 6.5. EPSS: 2% chance of exploitation in the next 30 days.

Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshotter (<v0.4.2, <v1.0.2, v1.1, <1.2.2), and external-resizer (v0.1, v0.2) could result in unauthorized PersistentVolume data access or volume mutation during snapshot, restore from snapshot, cloning and resizing operations.

Affected products

  • Kubernetes External-Provisioner: from 0.4.1, up to and including 0.4.2; from 1.0.0, up to and including 1.0.1; from 1.1.0, up to and including 1.2.1; version 1.3.0 only
  • Kubernetes External-Resizer: from 0.1.0, up to and including 0.2.0
  • Kubernetes External-Snapshotter: from 0.4.0, up to and including 0.4.1; from 1.0.0, up to and including 1.0.1; from 1.1.0, up to and including 1.2.1
  • Red Hat Openshift Container Platform: version 3.11 only; version 4.1 only; version 4.2 only

Published 2019-12-05. Last modified 2026-06-17.