Beveiligingsadvies

CVE-2026-6437

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-04-17 18:41:36
Laatst bijgewerkt 2026-04-17 19:57:02
Toegewezen door AMZN
CVSS-score 6.9
Status PUBLISHED

Beschrijving

Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) before v3.0.1 allows remote authenticated users with PersistentVolume creation permissions to inject arbitrary mount options via comma injection. To remediate this issue, users should upgrade to version v3.0.1