Database/Control plane, storage & DevOps
Pure Storage FlashArray Purity (array admin command execution): A user holding the array admin role executes arbitrary
CVE-2024-0004Control plane, storage & DevOpscurated
Impact
A user holding the array admin role executes arbitrary commands remotely and escalates beyond the intended management boundary onto the array's underlying OS.
Who can reach it
Authenticated array admin.
What to do
Apply the Purity update from Pure's security page.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.