GPU VulnDB

Database/Control plane, storage & DevOps

IBM Spectrum Scale administrative command path: A local unprivileged user becomes root on a Storage Scale node by

CVE-2019-4558Control plane, storage & DevOpscurated

Impact

A local unprivileged user becomes root on a Storage Scale node by injecting parameters into an administrative code path. Root on a storage node means the node's entire filesystem namespace, keys and cluster credentials are exposed.

Who can reach it

Local shell on any node running Storage Scale 4.2.0.0-4.2.3.17 or 5.0.0.0-5.0.3.2. No network position needed.

What to do

Move to the fixed 4.2.3.18 / 5.0.3.3 level or later. Where an immediate upgrade is not possible, remove interactive shell access for non-admin users on storage and NSD server nodes.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.