github.com/kubernetes-sigs/aws-efs-csi-driver
Activity
- Latest release
- 2y ago
- Total releases
- 50
- Cadence
- ~21 days
- Last 12 months
- 0
Reach
- Stars
- —
Details
- First release
- Mar 13, 2019
| Version | Released | |
|---|---|---|
v1.7.7
patch
1 CVE
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev |
v1.7.7
patch
Dependencies (17)
+ 9 more |
|
v1.7.6
patch
1 CVE
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev |
v1.7.6
patch
Dependencies (17)
+ 9 more |
|
v1.7.5
patch
1 CVE
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev |
v1.7.5
patch
Dependencies (17)
+ 9 more |
|
v1.7.4
patch
1 CVE
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev |
v1.7.4
patch
Dependencies (17)
+ 9 more |
|
v1.7.3
patch
1 CVE
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev |
v1.7.3
patch
Dependencies (17)
+ 9 more |
|
v1.7.2
patch
1 CVE
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev |
v1.7.2
patch
Dependencies (17)
+ 9 more |
|
v1.7.1
patch
1 CVE
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev |
v1.7.1
patch
Dependencies (17)
+ 9 more |
|
v1.7.0
minor
1 CVE
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev |
v1.7.0
minor
Dependencies (17)
+ 9 more |
|
v1.6.0
minor
1 CVE
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev |
v1.6.0
minor
Dependencies (15)
+ 7 more |
|
v1.5.9
patch
1 CVE
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev |
v1.5.9
patch
Dependencies (15)
+ 7 more |
|
v1.5.8
patch
1 CVE
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev |
v1.5.8
patch
Dependencies (14)
+ 6 more |
|
v1.5.7
patch
1 CVE
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev |
v1.5.7
patch
Dependencies (14)
+ 6 more |
|
v1.5.6
patch
1 CVE
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev |
v1.5.6
patch
Dependencies (14)
+ 6 more |
|
v1.5.5
patch
1 CVE
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev |
v1.5.5
patch
Dependencies (14)
+ 6 more |
|
v1.5.4
patch
1 CVE
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev |
v1.5.4
patch
Dependencies (14)
+ 6 more |
|
v1.5.3
patch
1 CVE
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev |
v1.5.3
patch
Dependencies (14)
+ 6 more |
|
v1.5.2
patch
1 CVE
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev |
v1.5.2
patch
Dependencies (14)
+ 6 more |
|
v1.5.1
patch
1 CVE
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev |
v1.5.1
patch
Dependencies (14)
+ 6 more |
|
v1.5.0
minor
1 CVE
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev |
v1.5.0
minor
Dependencies (14)
+ 6 more |
|
v1.4.9
patch
1 CVE
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev |
v1.4.9
patch
Dependencies (14)
+ 6 more |
|
v1.4.8
patch
1 CVE
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev |
v1.4.8
patch
Dependencies (14)
+ 6 more |
|
v1.4.7
patch
2 CVEs
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev
CVE-2022-46174
GHSA-4fv8-w65m-3932
Dec 30, 2022
efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
None
Low
Low
ImpactA potential race condition issue exists within the Amazon EFS mount helper in efs-utils versions v1.34.3 and below, and aws-efs-csi-driver versions v1.4.7 and below. When using TLS to mount file systems, the mount helper allocates a local port for stunnel to receive NFS connections prior to applying the TLS tunnel. In affected versions, concurrent mount operations can allocate the same local port, leading to either failed mount operations or an inappropriate mapping from an EFS customer’s local mount points to that customer’s EFS file systems. Affected versions: efs-utils <= v1.34.3, aws-efs-csi-driver <= v1.4.7 PatchesThe patches are included in efs-utils version v1.34.4 and newer, and in aws-efs-csi-driver v1.4.8 and newer. WorkaroundsThere is no recommended work around. We recommend affected users update the installed version of efs-utils to v1.34.4+ or aws-efs-csi-driver to v1.4.8+ to address this issue. Referenceshttps://github.com/aws/efs-utils/commit/f3a8f88167d55caa2f78aeb72d4dc1987a9ed62d https://github.com/aws/efs-utils/issues/125 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/282 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/635 Fixed in
1.4.8
References Updated Nov 08, 2023 · Source: OSV.dev |
v1.4.7
patch
Dependencies (14)
+ 6 more |
|
v1.4.6
patch
2 CVEs
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev
CVE-2022-46174
GHSA-4fv8-w65m-3932
Dec 30, 2022
efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
None
Low
Low
ImpactA potential race condition issue exists within the Amazon EFS mount helper in efs-utils versions v1.34.3 and below, and aws-efs-csi-driver versions v1.4.7 and below. When using TLS to mount file systems, the mount helper allocates a local port for stunnel to receive NFS connections prior to applying the TLS tunnel. In affected versions, concurrent mount operations can allocate the same local port, leading to either failed mount operations or an inappropriate mapping from an EFS customer’s local mount points to that customer’s EFS file systems. Affected versions: efs-utils <= v1.34.3, aws-efs-csi-driver <= v1.4.7 PatchesThe patches are included in efs-utils version v1.34.4 and newer, and in aws-efs-csi-driver v1.4.8 and newer. WorkaroundsThere is no recommended work around. We recommend affected users update the installed version of efs-utils to v1.34.4+ or aws-efs-csi-driver to v1.4.8+ to address this issue. Referenceshttps://github.com/aws/efs-utils/commit/f3a8f88167d55caa2f78aeb72d4dc1987a9ed62d https://github.com/aws/efs-utils/issues/125 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/282 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/635 Fixed in
1.4.8
References Updated Nov 08, 2023 · Source: OSV.dev |
v1.4.6
patch
Dependencies (14)
+ 6 more |
|
v1.4.5
patch
2 CVEs
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev
CVE-2022-46174
GHSA-4fv8-w65m-3932
Dec 30, 2022
efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
None
Low
Low
ImpactA potential race condition issue exists within the Amazon EFS mount helper in efs-utils versions v1.34.3 and below, and aws-efs-csi-driver versions v1.4.7 and below. When using TLS to mount file systems, the mount helper allocates a local port for stunnel to receive NFS connections prior to applying the TLS tunnel. In affected versions, concurrent mount operations can allocate the same local port, leading to either failed mount operations or an inappropriate mapping from an EFS customer’s local mount points to that customer’s EFS file systems. Affected versions: efs-utils <= v1.34.3, aws-efs-csi-driver <= v1.4.7 PatchesThe patches are included in efs-utils version v1.34.4 and newer, and in aws-efs-csi-driver v1.4.8 and newer. WorkaroundsThere is no recommended work around. We recommend affected users update the installed version of efs-utils to v1.34.4+ or aws-efs-csi-driver to v1.4.8+ to address this issue. Referenceshttps://github.com/aws/efs-utils/commit/f3a8f88167d55caa2f78aeb72d4dc1987a9ed62d https://github.com/aws/efs-utils/issues/125 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/282 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/635 Fixed in
1.4.8
References Updated Nov 08, 2023 · Source: OSV.dev |
v1.4.5
patch
Dependencies (14)
+ 6 more |
|
v1.4.4
patch
2 CVEs
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev
CVE-2022-46174
GHSA-4fv8-w65m-3932
Dec 30, 2022
efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
None
Low
Low
ImpactA potential race condition issue exists within the Amazon EFS mount helper in efs-utils versions v1.34.3 and below, and aws-efs-csi-driver versions v1.4.7 and below. When using TLS to mount file systems, the mount helper allocates a local port for stunnel to receive NFS connections prior to applying the TLS tunnel. In affected versions, concurrent mount operations can allocate the same local port, leading to either failed mount operations or an inappropriate mapping from an EFS customer’s local mount points to that customer’s EFS file systems. Affected versions: efs-utils <= v1.34.3, aws-efs-csi-driver <= v1.4.7 PatchesThe patches are included in efs-utils version v1.34.4 and newer, and in aws-efs-csi-driver v1.4.8 and newer. WorkaroundsThere is no recommended work around. We recommend affected users update the installed version of efs-utils to v1.34.4+ or aws-efs-csi-driver to v1.4.8+ to address this issue. Referenceshttps://github.com/aws/efs-utils/commit/f3a8f88167d55caa2f78aeb72d4dc1987a9ed62d https://github.com/aws/efs-utils/issues/125 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/282 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/635 Fixed in
1.4.8
References Updated Nov 08, 2023 · Source: OSV.dev |
v1.4.4
patch
Dependencies (14)
+ 6 more |
|
v1.4.3
patch
2 CVEs
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev
CVE-2022-46174
GHSA-4fv8-w65m-3932
Dec 30, 2022
efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
None
Low
Low
ImpactA potential race condition issue exists within the Amazon EFS mount helper in efs-utils versions v1.34.3 and below, and aws-efs-csi-driver versions v1.4.7 and below. When using TLS to mount file systems, the mount helper allocates a local port for stunnel to receive NFS connections prior to applying the TLS tunnel. In affected versions, concurrent mount operations can allocate the same local port, leading to either failed mount operations or an inappropriate mapping from an EFS customer’s local mount points to that customer’s EFS file systems. Affected versions: efs-utils <= v1.34.3, aws-efs-csi-driver <= v1.4.7 PatchesThe patches are included in efs-utils version v1.34.4 and newer, and in aws-efs-csi-driver v1.4.8 and newer. WorkaroundsThere is no recommended work around. We recommend affected users update the installed version of efs-utils to v1.34.4+ or aws-efs-csi-driver to v1.4.8+ to address this issue. Referenceshttps://github.com/aws/efs-utils/commit/f3a8f88167d55caa2f78aeb72d4dc1987a9ed62d https://github.com/aws/efs-utils/issues/125 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/282 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/635 Fixed in
1.4.8
References Updated Nov 08, 2023 · Source: OSV.dev |
v1.4.3
patch
Dependencies (14)
+ 6 more |
|
v1.4.2
patch
2 CVEs
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev
CVE-2022-46174
GHSA-4fv8-w65m-3932
Dec 30, 2022
efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
None
Low
Low
ImpactA potential race condition issue exists within the Amazon EFS mount helper in efs-utils versions v1.34.3 and below, and aws-efs-csi-driver versions v1.4.7 and below. When using TLS to mount file systems, the mount helper allocates a local port for stunnel to receive NFS connections prior to applying the TLS tunnel. In affected versions, concurrent mount operations can allocate the same local port, leading to either failed mount operations or an inappropriate mapping from an EFS customer’s local mount points to that customer’s EFS file systems. Affected versions: efs-utils <= v1.34.3, aws-efs-csi-driver <= v1.4.7 PatchesThe patches are included in efs-utils version v1.34.4 and newer, and in aws-efs-csi-driver v1.4.8 and newer. WorkaroundsThere is no recommended work around. We recommend affected users update the installed version of efs-utils to v1.34.4+ or aws-efs-csi-driver to v1.4.8+ to address this issue. Referenceshttps://github.com/aws/efs-utils/commit/f3a8f88167d55caa2f78aeb72d4dc1987a9ed62d https://github.com/aws/efs-utils/issues/125 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/282 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/635 Fixed in
1.4.8
References Updated Nov 08, 2023 · Source: OSV.dev |
v1.4.2
patch
Dependencies (14)
+ 6 more |
|
v1.4.1
patch
2 CVEs
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev
CVE-2022-46174
GHSA-4fv8-w65m-3932
Dec 30, 2022
efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
None
Low
Low
ImpactA potential race condition issue exists within the Amazon EFS mount helper in efs-utils versions v1.34.3 and below, and aws-efs-csi-driver versions v1.4.7 and below. When using TLS to mount file systems, the mount helper allocates a local port for stunnel to receive NFS connections prior to applying the TLS tunnel. In affected versions, concurrent mount operations can allocate the same local port, leading to either failed mount operations or an inappropriate mapping from an EFS customer’s local mount points to that customer’s EFS file systems. Affected versions: efs-utils <= v1.34.3, aws-efs-csi-driver <= v1.4.7 PatchesThe patches are included in efs-utils version v1.34.4 and newer, and in aws-efs-csi-driver v1.4.8 and newer. WorkaroundsThere is no recommended work around. We recommend affected users update the installed version of efs-utils to v1.34.4+ or aws-efs-csi-driver to v1.4.8+ to address this issue. Referenceshttps://github.com/aws/efs-utils/commit/f3a8f88167d55caa2f78aeb72d4dc1987a9ed62d https://github.com/aws/efs-utils/issues/125 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/282 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/635 Fixed in
1.4.8
References Updated Nov 08, 2023 · Source: OSV.dev |
v1.4.1
patch
Dependencies (14)
+ 6 more |
|
v1.4.0
minor
2 CVEs
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev
CVE-2022-46174
GHSA-4fv8-w65m-3932
Dec 30, 2022
efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
None
Low
Low
ImpactA potential race condition issue exists within the Amazon EFS mount helper in efs-utils versions v1.34.3 and below, and aws-efs-csi-driver versions v1.4.7 and below. When using TLS to mount file systems, the mount helper allocates a local port for stunnel to receive NFS connections prior to applying the TLS tunnel. In affected versions, concurrent mount operations can allocate the same local port, leading to either failed mount operations or an inappropriate mapping from an EFS customer’s local mount points to that customer’s EFS file systems. Affected versions: efs-utils <= v1.34.3, aws-efs-csi-driver <= v1.4.7 PatchesThe patches are included in efs-utils version v1.34.4 and newer, and in aws-efs-csi-driver v1.4.8 and newer. WorkaroundsThere is no recommended work around. We recommend affected users update the installed version of efs-utils to v1.34.4+ or aws-efs-csi-driver to v1.4.8+ to address this issue. Referenceshttps://github.com/aws/efs-utils/commit/f3a8f88167d55caa2f78aeb72d4dc1987a9ed62d https://github.com/aws/efs-utils/issues/125 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/282 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/635 Fixed in
1.4.8
References Updated Nov 08, 2023 · Source: OSV.dev |
v1.4.0
minor
Dependencies (14)
+ 6 more |
|
v1.3.8
patch
2 CVEs
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev
CVE-2022-46174
GHSA-4fv8-w65m-3932
Dec 30, 2022
efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
None
Low
Low
ImpactA potential race condition issue exists within the Amazon EFS mount helper in efs-utils versions v1.34.3 and below, and aws-efs-csi-driver versions v1.4.7 and below. When using TLS to mount file systems, the mount helper allocates a local port for stunnel to receive NFS connections prior to applying the TLS tunnel. In affected versions, concurrent mount operations can allocate the same local port, leading to either failed mount operations or an inappropriate mapping from an EFS customer’s local mount points to that customer’s EFS file systems. Affected versions: efs-utils <= v1.34.3, aws-efs-csi-driver <= v1.4.7 PatchesThe patches are included in efs-utils version v1.34.4 and newer, and in aws-efs-csi-driver v1.4.8 and newer. WorkaroundsThere is no recommended work around. We recommend affected users update the installed version of efs-utils to v1.34.4+ or aws-efs-csi-driver to v1.4.8+ to address this issue. Referenceshttps://github.com/aws/efs-utils/commit/f3a8f88167d55caa2f78aeb72d4dc1987a9ed62d https://github.com/aws/efs-utils/issues/125 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/282 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/635 Fixed in
1.4.8
References Updated Nov 08, 2023 · Source: OSV.dev |
v1.3.8
patch
Dependencies (14)
+ 6 more |
|
v1.3.7
patch
2 CVEs
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev
CVE-2022-46174
GHSA-4fv8-w65m-3932
Dec 30, 2022
efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
None
Low
Low
ImpactA potential race condition issue exists within the Amazon EFS mount helper in efs-utils versions v1.34.3 and below, and aws-efs-csi-driver versions v1.4.7 and below. When using TLS to mount file systems, the mount helper allocates a local port for stunnel to receive NFS connections prior to applying the TLS tunnel. In affected versions, concurrent mount operations can allocate the same local port, leading to either failed mount operations or an inappropriate mapping from an EFS customer’s local mount points to that customer’s EFS file systems. Affected versions: efs-utils <= v1.34.3, aws-efs-csi-driver <= v1.4.7 PatchesThe patches are included in efs-utils version v1.34.4 and newer, and in aws-efs-csi-driver v1.4.8 and newer. WorkaroundsThere is no recommended work around. We recommend affected users update the installed version of efs-utils to v1.34.4+ or aws-efs-csi-driver to v1.4.8+ to address this issue. Referenceshttps://github.com/aws/efs-utils/commit/f3a8f88167d55caa2f78aeb72d4dc1987a9ed62d https://github.com/aws/efs-utils/issues/125 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/282 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/635 Fixed in
1.4.8
References Updated Nov 08, 2023 · Source: OSV.dev |
v1.3.7
patch
Dependencies (14)
+ 6 more |
|
v1.3.6
patch
2 CVEs
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev
CVE-2022-46174
GHSA-4fv8-w65m-3932
Dec 30, 2022
efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
None
Low
Low
ImpactA potential race condition issue exists within the Amazon EFS mount helper in efs-utils versions v1.34.3 and below, and aws-efs-csi-driver versions v1.4.7 and below. When using TLS to mount file systems, the mount helper allocates a local port for stunnel to receive NFS connections prior to applying the TLS tunnel. In affected versions, concurrent mount operations can allocate the same local port, leading to either failed mount operations or an inappropriate mapping from an EFS customer’s local mount points to that customer’s EFS file systems. Affected versions: efs-utils <= v1.34.3, aws-efs-csi-driver <= v1.4.7 PatchesThe patches are included in efs-utils version v1.34.4 and newer, and in aws-efs-csi-driver v1.4.8 and newer. WorkaroundsThere is no recommended work around. We recommend affected users update the installed version of efs-utils to v1.34.4+ or aws-efs-csi-driver to v1.4.8+ to address this issue. Referenceshttps://github.com/aws/efs-utils/commit/f3a8f88167d55caa2f78aeb72d4dc1987a9ed62d https://github.com/aws/efs-utils/issues/125 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/282 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/635 Fixed in
1.4.8
References Updated Nov 08, 2023 · Source: OSV.dev |
v1.3.6
patch
Dependencies (14)
+ 6 more |
|
v1.3.5
patch
2 CVEs
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev
CVE-2022-46174
GHSA-4fv8-w65m-3932
Dec 30, 2022
efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
None
Low
Low
ImpactA potential race condition issue exists within the Amazon EFS mount helper in efs-utils versions v1.34.3 and below, and aws-efs-csi-driver versions v1.4.7 and below. When using TLS to mount file systems, the mount helper allocates a local port for stunnel to receive NFS connections prior to applying the TLS tunnel. In affected versions, concurrent mount operations can allocate the same local port, leading to either failed mount operations or an inappropriate mapping from an EFS customer’s local mount points to that customer’s EFS file systems. Affected versions: efs-utils <= v1.34.3, aws-efs-csi-driver <= v1.4.7 PatchesThe patches are included in efs-utils version v1.34.4 and newer, and in aws-efs-csi-driver v1.4.8 and newer. WorkaroundsThere is no recommended work around. We recommend affected users update the installed version of efs-utils to v1.34.4+ or aws-efs-csi-driver to v1.4.8+ to address this issue. Referenceshttps://github.com/aws/efs-utils/commit/f3a8f88167d55caa2f78aeb72d4dc1987a9ed62d https://github.com/aws/efs-utils/issues/125 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/282 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/635 Fixed in
1.4.8
References Updated Nov 08, 2023 · Source: OSV.dev |
v1.3.5
patch
Dependencies (14)
+ 6 more |
|
v1.3.4
patch
2 CVEs
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev
CVE-2022-46174
GHSA-4fv8-w65m-3932
Dec 30, 2022
efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
None
Low
Low
ImpactA potential race condition issue exists within the Amazon EFS mount helper in efs-utils versions v1.34.3 and below, and aws-efs-csi-driver versions v1.4.7 and below. When using TLS to mount file systems, the mount helper allocates a local port for stunnel to receive NFS connections prior to applying the TLS tunnel. In affected versions, concurrent mount operations can allocate the same local port, leading to either failed mount operations or an inappropriate mapping from an EFS customer’s local mount points to that customer’s EFS file systems. Affected versions: efs-utils <= v1.34.3, aws-efs-csi-driver <= v1.4.7 PatchesThe patches are included in efs-utils version v1.34.4 and newer, and in aws-efs-csi-driver v1.4.8 and newer. WorkaroundsThere is no recommended work around. We recommend affected users update the installed version of efs-utils to v1.34.4+ or aws-efs-csi-driver to v1.4.8+ to address this issue. Referenceshttps://github.com/aws/efs-utils/commit/f3a8f88167d55caa2f78aeb72d4dc1987a9ed62d https://github.com/aws/efs-utils/issues/125 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/282 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/635 Fixed in
1.4.8
References Updated Nov 08, 2023 · Source: OSV.dev |
v1.3.4
patch
Dependencies (14)
+ 6 more |
|
v1.3.3
patch
2 CVEs
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev
CVE-2022-46174
GHSA-4fv8-w65m-3932
Dec 30, 2022
efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
None
Low
Low
ImpactA potential race condition issue exists within the Amazon EFS mount helper in efs-utils versions v1.34.3 and below, and aws-efs-csi-driver versions v1.4.7 and below. When using TLS to mount file systems, the mount helper allocates a local port for stunnel to receive NFS connections prior to applying the TLS tunnel. In affected versions, concurrent mount operations can allocate the same local port, leading to either failed mount operations or an inappropriate mapping from an EFS customer’s local mount points to that customer’s EFS file systems. Affected versions: efs-utils <= v1.34.3, aws-efs-csi-driver <= v1.4.7 PatchesThe patches are included in efs-utils version v1.34.4 and newer, and in aws-efs-csi-driver v1.4.8 and newer. WorkaroundsThere is no recommended work around. We recommend affected users update the installed version of efs-utils to v1.34.4+ or aws-efs-csi-driver to v1.4.8+ to address this issue. Referenceshttps://github.com/aws/efs-utils/commit/f3a8f88167d55caa2f78aeb72d4dc1987a9ed62d https://github.com/aws/efs-utils/issues/125 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/282 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/635 Fixed in
1.4.8
References Updated Nov 08, 2023 · Source: OSV.dev |
v1.3.3
patch
Dependencies (14)
+ 6 more |
|
v1.3.2
patch
2 CVEs
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev
CVE-2022-46174
GHSA-4fv8-w65m-3932
Dec 30, 2022
efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
None
Low
Low
ImpactA potential race condition issue exists within the Amazon EFS mount helper in efs-utils versions v1.34.3 and below, and aws-efs-csi-driver versions v1.4.7 and below. When using TLS to mount file systems, the mount helper allocates a local port for stunnel to receive NFS connections prior to applying the TLS tunnel. In affected versions, concurrent mount operations can allocate the same local port, leading to either failed mount operations or an inappropriate mapping from an EFS customer’s local mount points to that customer’s EFS file systems. Affected versions: efs-utils <= v1.34.3, aws-efs-csi-driver <= v1.4.7 PatchesThe patches are included in efs-utils version v1.34.4 and newer, and in aws-efs-csi-driver v1.4.8 and newer. WorkaroundsThere is no recommended work around. We recommend affected users update the installed version of efs-utils to v1.34.4+ or aws-efs-csi-driver to v1.4.8+ to address this issue. Referenceshttps://github.com/aws/efs-utils/commit/f3a8f88167d55caa2f78aeb72d4dc1987a9ed62d https://github.com/aws/efs-utils/issues/125 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/282 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/635 Fixed in
1.4.8
References Updated Nov 08, 2023 · Source: OSV.dev |
v1.3.2
patch
Dependencies (14)
+ 6 more |
|
v1.3.1
patch
2 CVEs
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev
CVE-2022-46174
GHSA-4fv8-w65m-3932
Dec 30, 2022
efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
None
Low
Low
ImpactA potential race condition issue exists within the Amazon EFS mount helper in efs-utils versions v1.34.3 and below, and aws-efs-csi-driver versions v1.4.7 and below. When using TLS to mount file systems, the mount helper allocates a local port for stunnel to receive NFS connections prior to applying the TLS tunnel. In affected versions, concurrent mount operations can allocate the same local port, leading to either failed mount operations or an inappropriate mapping from an EFS customer’s local mount points to that customer’s EFS file systems. Affected versions: efs-utils <= v1.34.3, aws-efs-csi-driver <= v1.4.7 PatchesThe patches are included in efs-utils version v1.34.4 and newer, and in aws-efs-csi-driver v1.4.8 and newer. WorkaroundsThere is no recommended work around. We recommend affected users update the installed version of efs-utils to v1.34.4+ or aws-efs-csi-driver to v1.4.8+ to address this issue. Referenceshttps://github.com/aws/efs-utils/commit/f3a8f88167d55caa2f78aeb72d4dc1987a9ed62d https://github.com/aws/efs-utils/issues/125 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/282 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/635 Fixed in
1.4.8
References Updated Nov 08, 2023 · Source: OSV.dev |
v1.3.1
patch
Dependencies (14)
+ 6 more |
|
v1.3.0
minor
2 CVEs
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev
CVE-2022-46174
GHSA-4fv8-w65m-3932
Dec 30, 2022
efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
None
Low
Low
ImpactA potential race condition issue exists within the Amazon EFS mount helper in efs-utils versions v1.34.3 and below, and aws-efs-csi-driver versions v1.4.7 and below. When using TLS to mount file systems, the mount helper allocates a local port for stunnel to receive NFS connections prior to applying the TLS tunnel. In affected versions, concurrent mount operations can allocate the same local port, leading to either failed mount operations or an inappropriate mapping from an EFS customer’s local mount points to that customer’s EFS file systems. Affected versions: efs-utils <= v1.34.3, aws-efs-csi-driver <= v1.4.7 PatchesThe patches are included in efs-utils version v1.34.4 and newer, and in aws-efs-csi-driver v1.4.8 and newer. WorkaroundsThere is no recommended work around. We recommend affected users update the installed version of efs-utils to v1.34.4+ or aws-efs-csi-driver to v1.4.8+ to address this issue. Referenceshttps://github.com/aws/efs-utils/commit/f3a8f88167d55caa2f78aeb72d4dc1987a9ed62d https://github.com/aws/efs-utils/issues/125 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/282 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/635 Fixed in
1.4.8
References Updated Nov 08, 2023 · Source: OSV.dev |
v1.3.0
minor
Dependencies (14)
+ 6 more |
|
v1.2.1
patch
2 CVEs
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev
CVE-2022-46174
GHSA-4fv8-w65m-3932
Dec 30, 2022
efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
None
Low
Low
ImpactA potential race condition issue exists within the Amazon EFS mount helper in efs-utils versions v1.34.3 and below, and aws-efs-csi-driver versions v1.4.7 and below. When using TLS to mount file systems, the mount helper allocates a local port for stunnel to receive NFS connections prior to applying the TLS tunnel. In affected versions, concurrent mount operations can allocate the same local port, leading to either failed mount operations or an inappropriate mapping from an EFS customer’s local mount points to that customer’s EFS file systems. Affected versions: efs-utils <= v1.34.3, aws-efs-csi-driver <= v1.4.7 PatchesThe patches are included in efs-utils version v1.34.4 and newer, and in aws-efs-csi-driver v1.4.8 and newer. WorkaroundsThere is no recommended work around. We recommend affected users update the installed version of efs-utils to v1.34.4+ or aws-efs-csi-driver to v1.4.8+ to address this issue. Referenceshttps://github.com/aws/efs-utils/commit/f3a8f88167d55caa2f78aeb72d4dc1987a9ed62d https://github.com/aws/efs-utils/issues/125 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/282 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/635 Fixed in
1.4.8
References Updated Nov 08, 2023 · Source: OSV.dev |
v1.2.1
patch
Dependencies (14)
+ 6 more |
|
v1.2.0
minor
2 CVEs
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev
CVE-2022-46174
GHSA-4fv8-w65m-3932
Dec 30, 2022
efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
None
Low
Low
ImpactA potential race condition issue exists within the Amazon EFS mount helper in efs-utils versions v1.34.3 and below, and aws-efs-csi-driver versions v1.4.7 and below. When using TLS to mount file systems, the mount helper allocates a local port for stunnel to receive NFS connections prior to applying the TLS tunnel. In affected versions, concurrent mount operations can allocate the same local port, leading to either failed mount operations or an inappropriate mapping from an EFS customer’s local mount points to that customer’s EFS file systems. Affected versions: efs-utils <= v1.34.3, aws-efs-csi-driver <= v1.4.7 PatchesThe patches are included in efs-utils version v1.34.4 and newer, and in aws-efs-csi-driver v1.4.8 and newer. WorkaroundsThere is no recommended work around. We recommend affected users update the installed version of efs-utils to v1.34.4+ or aws-efs-csi-driver to v1.4.8+ to address this issue. Referenceshttps://github.com/aws/efs-utils/commit/f3a8f88167d55caa2f78aeb72d4dc1987a9ed62d https://github.com/aws/efs-utils/issues/125 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/282 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/635 Fixed in
1.4.8
References Updated Nov 08, 2023 · Source: OSV.dev |
v1.2.0
minor
Dependencies (14)
+ 6 more |
|
v1.1.1
patch
2 CVEs
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev
CVE-2022-46174
GHSA-4fv8-w65m-3932
Dec 30, 2022
efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
None
Low
Low
ImpactA potential race condition issue exists within the Amazon EFS mount helper in efs-utils versions v1.34.3 and below, and aws-efs-csi-driver versions v1.4.7 and below. When using TLS to mount file systems, the mount helper allocates a local port for stunnel to receive NFS connections prior to applying the TLS tunnel. In affected versions, concurrent mount operations can allocate the same local port, leading to either failed mount operations or an inappropriate mapping from an EFS customer’s local mount points to that customer’s EFS file systems. Affected versions: efs-utils <= v1.34.3, aws-efs-csi-driver <= v1.4.7 PatchesThe patches are included in efs-utils version v1.34.4 and newer, and in aws-efs-csi-driver v1.4.8 and newer. WorkaroundsThere is no recommended work around. We recommend affected users update the installed version of efs-utils to v1.34.4+ or aws-efs-csi-driver to v1.4.8+ to address this issue. Referenceshttps://github.com/aws/efs-utils/commit/f3a8f88167d55caa2f78aeb72d4dc1987a9ed62d https://github.com/aws/efs-utils/issues/125 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/282 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/635 Fixed in
1.4.8
References Updated Nov 08, 2023 · Source: OSV.dev |
v1.1.1
patch
Dependencies (13)
+ 5 more |
|
v1.1.0-rc.0
pre
2 CVEs
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev
CVE-2022-46174
GHSA-4fv8-w65m-3932
Dec 30, 2022
efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
None
Low
Low
ImpactA potential race condition issue exists within the Amazon EFS mount helper in efs-utils versions v1.34.3 and below, and aws-efs-csi-driver versions v1.4.7 and below. When using TLS to mount file systems, the mount helper allocates a local port for stunnel to receive NFS connections prior to applying the TLS tunnel. In affected versions, concurrent mount operations can allocate the same local port, leading to either failed mount operations or an inappropriate mapping from an EFS customer’s local mount points to that customer’s EFS file systems. Affected versions: efs-utils <= v1.34.3, aws-efs-csi-driver <= v1.4.7 PatchesThe patches are included in efs-utils version v1.34.4 and newer, and in aws-efs-csi-driver v1.4.8 and newer. WorkaroundsThere is no recommended work around. We recommend affected users update the installed version of efs-utils to v1.34.4+ or aws-efs-csi-driver to v1.4.8+ to address this issue. Referenceshttps://github.com/aws/efs-utils/commit/f3a8f88167d55caa2f78aeb72d4dc1987a9ed62d https://github.com/aws/efs-utils/issues/125 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/282 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/635 Fixed in
1.4.8
References Updated Nov 08, 2023 · Source: OSV.dev |
v1.1.0-rc.0
pre
Dependencies (13)
+ 5 more |
|
v1.1.0
minor
2 CVEs
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev
CVE-2022-46174
GHSA-4fv8-w65m-3932
Dec 30, 2022
efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
None
Low
Low
ImpactA potential race condition issue exists within the Amazon EFS mount helper in efs-utils versions v1.34.3 and below, and aws-efs-csi-driver versions v1.4.7 and below. When using TLS to mount file systems, the mount helper allocates a local port for stunnel to receive NFS connections prior to applying the TLS tunnel. In affected versions, concurrent mount operations can allocate the same local port, leading to either failed mount operations or an inappropriate mapping from an EFS customer’s local mount points to that customer’s EFS file systems. Affected versions: efs-utils <= v1.34.3, aws-efs-csi-driver <= v1.4.7 PatchesThe patches are included in efs-utils version v1.34.4 and newer, and in aws-efs-csi-driver v1.4.8 and newer. WorkaroundsThere is no recommended work around. We recommend affected users update the installed version of efs-utils to v1.34.4+ or aws-efs-csi-driver to v1.4.8+ to address this issue. Referenceshttps://github.com/aws/efs-utils/commit/f3a8f88167d55caa2f78aeb72d4dc1987a9ed62d https://github.com/aws/efs-utils/issues/125 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/282 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/635 Fixed in
1.4.8
References Updated Nov 08, 2023 · Source: OSV.dev |
v1.1.0
minor
Dependencies (13)
+ 5 more |
|
v1.0.0
major
2 CVEs
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev
CVE-2022-46174
GHSA-4fv8-w65m-3932
Dec 30, 2022
efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
None
Low
Low
ImpactA potential race condition issue exists within the Amazon EFS mount helper in efs-utils versions v1.34.3 and below, and aws-efs-csi-driver versions v1.4.7 and below. When using TLS to mount file systems, the mount helper allocates a local port for stunnel to receive NFS connections prior to applying the TLS tunnel. In affected versions, concurrent mount operations can allocate the same local port, leading to either failed mount operations or an inappropriate mapping from an EFS customer’s local mount points to that customer’s EFS file systems. Affected versions: efs-utils <= v1.34.3, aws-efs-csi-driver <= v1.4.7 PatchesThe patches are included in efs-utils version v1.34.4 and newer, and in aws-efs-csi-driver v1.4.8 and newer. WorkaroundsThere is no recommended work around. We recommend affected users update the installed version of efs-utils to v1.34.4+ or aws-efs-csi-driver to v1.4.8+ to address this issue. Referenceshttps://github.com/aws/efs-utils/commit/f3a8f88167d55caa2f78aeb72d4dc1987a9ed62d https://github.com/aws/efs-utils/issues/125 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/282 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/635 Fixed in
1.4.8
References Updated Nov 08, 2023 · Source: OSV.dev |
v1.0.0
major
Dependencies (13)
+ 5 more |
|
v0.3.0
minor
2 CVEs
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev
CVE-2022-46174
GHSA-4fv8-w65m-3932
Dec 30, 2022
efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
None
Low
Low
ImpactA potential race condition issue exists within the Amazon EFS mount helper in efs-utils versions v1.34.3 and below, and aws-efs-csi-driver versions v1.4.7 and below. When using TLS to mount file systems, the mount helper allocates a local port for stunnel to receive NFS connections prior to applying the TLS tunnel. In affected versions, concurrent mount operations can allocate the same local port, leading to either failed mount operations or an inappropriate mapping from an EFS customer’s local mount points to that customer’s EFS file systems. Affected versions: efs-utils <= v1.34.3, aws-efs-csi-driver <= v1.4.7 PatchesThe patches are included in efs-utils version v1.34.4 and newer, and in aws-efs-csi-driver v1.4.8 and newer. WorkaroundsThere is no recommended work around. We recommend affected users update the installed version of efs-utils to v1.34.4+ or aws-efs-csi-driver to v1.4.8+ to address this issue. Referenceshttps://github.com/aws/efs-utils/commit/f3a8f88167d55caa2f78aeb72d4dc1987a9ed62d https://github.com/aws/efs-utils/issues/125 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/282 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/635 Fixed in
1.4.8
References Updated Nov 08, 2023 · Source: OSV.dev |
v0.3.0
minor
Dependencies (11)
+ 3 more |
|
v0.3.0-rc0
pre
2 CVEs
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev
CVE-2022-46174
GHSA-4fv8-w65m-3932
Dec 30, 2022
efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
None
Low
Low
ImpactA potential race condition issue exists within the Amazon EFS mount helper in efs-utils versions v1.34.3 and below, and aws-efs-csi-driver versions v1.4.7 and below. When using TLS to mount file systems, the mount helper allocates a local port for stunnel to receive NFS connections prior to applying the TLS tunnel. In affected versions, concurrent mount operations can allocate the same local port, leading to either failed mount operations or an inappropriate mapping from an EFS customer’s local mount points to that customer’s EFS file systems. Affected versions: efs-utils <= v1.34.3, aws-efs-csi-driver <= v1.4.7 PatchesThe patches are included in efs-utils version v1.34.4 and newer, and in aws-efs-csi-driver v1.4.8 and newer. WorkaroundsThere is no recommended work around. We recommend affected users update the installed version of efs-utils to v1.34.4+ or aws-efs-csi-driver to v1.4.8+ to address this issue. Referenceshttps://github.com/aws/efs-utils/commit/f3a8f88167d55caa2f78aeb72d4dc1987a9ed62d https://github.com/aws/efs-utils/issues/125 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/282 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/635 Fixed in
1.4.8
References Updated Nov 08, 2023 · Source: OSV.dev |
v0.3.0-rc0
pre
Dependencies (11)
+ 3 more |
|
v0.2.0
minor
2 CVEs
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev
CVE-2022-46174
GHSA-4fv8-w65m-3932
Dec 30, 2022
efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
None
Low
Low
ImpactA potential race condition issue exists within the Amazon EFS mount helper in efs-utils versions v1.34.3 and below, and aws-efs-csi-driver versions v1.4.7 and below. When using TLS to mount file systems, the mount helper allocates a local port for stunnel to receive NFS connections prior to applying the TLS tunnel. In affected versions, concurrent mount operations can allocate the same local port, leading to either failed mount operations or an inappropriate mapping from an EFS customer’s local mount points to that customer’s EFS file systems. Affected versions: efs-utils <= v1.34.3, aws-efs-csi-driver <= v1.4.7 PatchesThe patches are included in efs-utils version v1.34.4 and newer, and in aws-efs-csi-driver v1.4.8 and newer. WorkaroundsThere is no recommended work around. We recommend affected users update the installed version of efs-utils to v1.34.4+ or aws-efs-csi-driver to v1.4.8+ to address this issue. Referenceshttps://github.com/aws/efs-utils/commit/f3a8f88167d55caa2f78aeb72d4dc1987a9ed62d https://github.com/aws/efs-utils/issues/125 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/282 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/635 Fixed in
1.4.8
References Updated Nov 08, 2023 · Source: OSV.dev |
v0.2.0
minor
Dependencies (7)
|
|
v0.2.0-rc0
pre
2 CVEs
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev
CVE-2022-46174
GHSA-4fv8-w65m-3932
Dec 30, 2022
efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
None
Low
Low
ImpactA potential race condition issue exists within the Amazon EFS mount helper in efs-utils versions v1.34.3 and below, and aws-efs-csi-driver versions v1.4.7 and below. When using TLS to mount file systems, the mount helper allocates a local port for stunnel to receive NFS connections prior to applying the TLS tunnel. In affected versions, concurrent mount operations can allocate the same local port, leading to either failed mount operations or an inappropriate mapping from an EFS customer’s local mount points to that customer’s EFS file systems. Affected versions: efs-utils <= v1.34.3, aws-efs-csi-driver <= v1.4.7 PatchesThe patches are included in efs-utils version v1.34.4 and newer, and in aws-efs-csi-driver v1.4.8 and newer. WorkaroundsThere is no recommended work around. We recommend affected users update the installed version of efs-utils to v1.34.4+ or aws-efs-csi-driver to v1.4.8+ to address this issue. Referenceshttps://github.com/aws/efs-utils/commit/f3a8f88167d55caa2f78aeb72d4dc1987a9ed62d https://github.com/aws/efs-utils/issues/125 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/282 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/635 Fixed in
1.4.8
References Updated Nov 08, 2023 · Source: OSV.dev |
v0.2.0-rc0
pre
Dependencies (7)
|
|
v0.1.0
initial
2 CVEs
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev
CVE-2022-46174
GHSA-4fv8-w65m-3932
Dec 30, 2022
efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
None
Low
Low
ImpactA potential race condition issue exists within the Amazon EFS mount helper in efs-utils versions v1.34.3 and below, and aws-efs-csi-driver versions v1.4.7 and below. When using TLS to mount file systems, the mount helper allocates a local port for stunnel to receive NFS connections prior to applying the TLS tunnel. In affected versions, concurrent mount operations can allocate the same local port, leading to either failed mount operations or an inappropriate mapping from an EFS customer’s local mount points to that customer’s EFS file systems. Affected versions: efs-utils <= v1.34.3, aws-efs-csi-driver <= v1.4.7 PatchesThe patches are included in efs-utils version v1.34.4 and newer, and in aws-efs-csi-driver v1.4.8 and newer. WorkaroundsThere is no recommended work around. We recommend affected users update the installed version of efs-utils to v1.34.4+ or aws-efs-csi-driver to v1.4.8+ to address this issue. Referenceshttps://github.com/aws/efs-utils/commit/f3a8f88167d55caa2f78aeb72d4dc1987a9ed62d https://github.com/aws/efs-utils/issues/125 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/282 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/635 Fixed in
1.4.8
References Updated Nov 08, 2023 · Source: OSV.dev |
v0.1.0
initial
Dependencies (6)
|
|
v0.1.0-rc0
pre
2 CVEs
CVE-2026-6437
GHSA-mph4-q2vm-w2pw
Apr 18, 2026
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
Medium
Network
Low
High
None
SummaryThe Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options. ImpactAn actor with PersistentVolume creation privileges can inject arbitrary mount options by appending comma-separated values to the Access Point ID in volumeHandle or to the mounttargetip volumeAttribute. The mount utility parses comma-separated values as separate options, causing the injected options to be applied to the filesystem mount without authorization. Impacted versions: <= v3.0.0 PatchesThis issue has been addressed in Amazon EFS CSI Driver version v3.0.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. WorkaroundsRestrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. ReferencesIf you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementWe would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Fixed in
1.7.8-0.20260416142831-51806c22c575
References
Updated Apr 18, 2026 · Source: OSV.dev
CVE-2022-46174
GHSA-4fv8-w65m-3932
Dec 30, 2022
efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts
4.2
/ 10
Medium
Network
High
Low
None
Unchanged
None
Low
Low
ImpactA potential race condition issue exists within the Amazon EFS mount helper in efs-utils versions v1.34.3 and below, and aws-efs-csi-driver versions v1.4.7 and below. When using TLS to mount file systems, the mount helper allocates a local port for stunnel to receive NFS connections prior to applying the TLS tunnel. In affected versions, concurrent mount operations can allocate the same local port, leading to either failed mount operations or an inappropriate mapping from an EFS customer’s local mount points to that customer’s EFS file systems. Affected versions: efs-utils <= v1.34.3, aws-efs-csi-driver <= v1.4.7 PatchesThe patches are included in efs-utils version v1.34.4 and newer, and in aws-efs-csi-driver v1.4.8 and newer. WorkaroundsThere is no recommended work around. We recommend affected users update the installed version of efs-utils to v1.34.4+ or aws-efs-csi-driver to v1.4.8+ to address this issue. Referenceshttps://github.com/aws/efs-utils/commit/f3a8f88167d55caa2f78aeb72d4dc1987a9ed62d https://github.com/aws/efs-utils/issues/125 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/282 https://github.com/kubernetes-sigs/aws-efs-csi-driver/issues/635 Fixed in
1.4.8
References Updated Nov 08, 2023 · Source: OSV.dev |
v0.1.0-rc0
pre
Dependencies (6)
|