Database/Control plane, storage & DevOps

IBM Spectrum Scale file audit logging: A local user touches files without the access being recorded, so the audit trail
CVE-2021-29671Control plane, storage & DevOpscurated
Impact
A local user touches files without the access being recorded, so the audit trail the operator relies on to prove who read what stops being complete. In a shared cluster this is the difference between detecting and not detecting a data-exfiltration incident.
Who can reach it
Local account on a Spectrum Scale 5.1.0.1 node with file audit logging enabled.
What to do
Upgrade to the fixed level. Treat audit logs written by 5.1.0.1 as incomplete rather than authoritative for any investigation covering that window.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.