Database/Control plane, storage & DevOps

HPE Cray Parallel Application Launch Service (PALS) authentication bypass: Authentication bypass in the service
Impact
Authentication bypass in the service that launches parallel jobs on Cray EX supercomputers. Bypassing PALS auth means launching arbitrary work on the cluster as another user - direct compromise of the HPC job-execution path.
Who can reach it
Unauthenticated network access to the PALS service on a Cray EX system.
What to do
Apply the HPE Cray fix per HPESBCR04653. This is a system-management-stack update on the Cray EX; coordinate with your Cray support contact because the update path is tied to the CSM release train, not a simple package bump.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.