Database/Control plane, storage & DevOps

IBM Spectrum Scale / GPFS node file access path: MULTI-TENANT ISOLATION: an unprivileged but authenticated user on a
Impact
MULTI-TENANT ISOLATION: an unprivileged but authenticated user on a GPFS node reads arbitrary files available to that node, which on a shared cluster includes other tenants' data and any credential material sitting on the node.
Who can reach it
An account on any GPFS node - the exact situation on a multi-user training cluster where researchers get shells on the same login or compute nodes.
What to do
Upgrade to the fixed Spectrum Scale level in IBM's bulletin (4.1.1.21 / 4.2.3.11 / 5.0.1.3 or later). Also re-check whether shared login nodes should mount the whole filesystem namespace at all, or only per-tenant filesets.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.