GPU VulnDB

Database/Control plane, storage & DevOps

IBM Storage Scale GUI (local privilege escalation): A local privilege escalation in the Storage Scale GUI available

CVE-2024-31891Control plane, storage & DevOpscurated

Impact

A local privilege escalation in the Storage Scale GUI available to an actor with command-line access to the GUI service account. Escalating to root on a GUI node is escalating on a node that holds cluster-wide storage credentials, which is why this scores higher operationally than 'it's just the web UI' suggests.

Who can reach it

Local, requires command-line access as the GUI service user on Storage Scale GUI 5.1.9.0-5.1.9.6 or 5.2.0.0-5.2.1.1.

What to do

Upgrade the Storage Scale GUI. Service-level upgrade with a restart; filesystem I/O is unaffected. Companion CSV-handling issue CVE-2024-31892 is fixed in the same range.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.