GPU VulnDB

Database/Control plane, storage & DevOps

IBM Spectrum Scale file audit logging: A local user touches files without the access being recorded, so the audit trail

CVE-2021-29671Control plane, storage & DevOpscurated

Impact

A local user touches files without the access being recorded, so the audit trail the operator relies on to prove who read what stops being complete. In a shared cluster this is the difference between detecting and not detecting a data-exfiltration incident.

Who can reach it

Local account on a Spectrum Scale 5.1.0.1 node with file audit logging enabled.

What to do

Upgrade to the fixed level. Treat audit logs written by 5.1.0.1 as incomplete rather than authoritative for any investigation covering that window.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.