Database/Control plane, storage & DevOps

IBM Spectrum Scale file audit logging: A local user touches files without the access being recorded, so the audit trail
CVSS 3.3CVE-2021-29671Control plane, storage & DevOpscurated
Impact
A local user touches files without the access being recorded, so the audit trail the operator relies on to prove who read what stops being complete. In a shared cluster this is the difference between detecting and not detecting a data-exfiltration incident.
Who can reach it
Local account on a Spectrum Scale 5.1.0.1 node with file audit logging enabled.
What to do
Upgrade to the fixed level. Treat audit logs written by 5.1.0.1 as incomplete rather than authoritative for any investigation covering that window.
References
Related entries
- Redis: Crafted Lua script triggers a NULL pointer dereferenceCVE-2022-24736 · RedisLow
- GitLab EE: pending members receive custom-role permissions before their membership is activeCVE-2025-9486 · GitLab EE (custom role assignment, pending membership state)Low
- Grafana: legacy correlation records can be read and permanently deleted across organizationsCVE-2026-21727 · Grafana (Correlations feature, legacy org_id = 0 records)Low
- RabbitMQ: Unsanitized username rendered in the management UICVE-2021-32718 · RabbitMQLow
- etcd: LeaseTimeToLive exposes key names to a user without read permission on those keysCVE-2023-32082 · etcdLow
- Prometheus / Thanos (golang-jwt): Unclear ParseWithClaims error behaviorCVE-2024-51744 · Prometheus / Thanos (golang-jwt)Low
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.