GPU VulnDB

Database/Control plane, storage & DevOps

IBM Spectrum Scale file audit logging retention: A privileged administrator deletes audit records before their

CVE-2021-38882Control plane, storage & DevOpscurated

Impact

A privileged administrator deletes audit records before their retention period expires, so an insider with admin rights can erase evidence of their own access to tenant data.

Who can reach it

Administrative access to a Spectrum Scale 5.1.0 through 5.1.1.1 cluster with file audit logging configured.

What to do

Upgrade to 5.1.1.2 or later. Independently, ship audit records off the cluster to append-only storage that cluster admins cannot reach, so the retention guarantee does not depend on the storage system policing its own administrators.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.