Malicious response from KubeEdge can crash CSI Driver controller server
CVE-2022-31077

4MEDIUM

Key Information:

Vendor

Kubeedge

Status
Vendor
CVE Published:
27 June 2022

What is CVE-2022-31077?

KubeEdge is built upon Kubernetes and extends native containerized application orchestration and device management to hosts at the Edge. In affected versions a malicious message response from KubeEdge can crash the CSI Driver controller server by triggering a nil-pointer dereference panic. As a consequence, the CSI Driver controller will be in denial of service. This bug has been fixed in Kubeedge 1.11.0, 1.10.1, and 1.9.3. Users should update to these versions to resolve the issue. At the time of writing, no workaround exists.

Affected Version(s)

kubeedge < 1.9.3 < 1.9.3

kubeedge >= 1.10.0, < 1.10.1 < 1.10.0, 1.10.1

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.