GPU VulnDB

Database/Control plane, storage & DevOps

IBM Spectrum Scale / GPFS node file access path: An unprivileged but authenticated user on a GPFS node reads arbitrary

CVE-2018-1723Control plane, storage & DevOpscurated

Impact

An unprivileged but authenticated user on a GPFS node reads arbitrary files available to that node, which on a shared cluster includes other tenants' data and any credential material sitting on the node.

Who can reach it

An account on any GPFS node - the exact situation on a multi-user training cluster where researchers get shells on the same login or compute nodes.

What to do

Upgrade to the fixed Spectrum Scale level in IBM's bulletin (4.1.1.21 / 4.2.3.11 / 5.0.1.3 or later). Also re-check whether shared login nodes should mount the whole filesystem namespace at all, or only per-tenant filesets.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.