Database/Control plane, storage & DevOps

IBM Spectrum Scale file audit logging retention: A privileged administrator deletes audit records before their
CVSS 4.4CVE-2021-38882Control plane, storage & DevOpscurated
Impact
A privileged administrator deletes audit records before their retention period expires, so an insider with admin rights can erase evidence of their own access to tenant data.
Who can reach it
Administrative access to a Spectrum Scale 5.1.0 through 5.1.1.1 cluster with file audit logging configured.
What to do
Upgrade to 5.1.1.2 or later. Independently, ship audit records off the cluster to append-only storage that cluster admins cannot reach, so the retention guarantee does not depend on the storage system policing its own administrators.
References
Related entries
- Windows Boot Manager: Secure Boot bypass exploited in the wild by the BlackLotus UEFI bootkitCVE-2022-21894 · Windows Boot ManagerMedium
- Redis: Malformed ACL selector triggers a server panicCVE-2024-51741 · RedisMedium
- GitLab EE: Owner or Maintainer can silently disable protected-environment deployment approvalsCVE-2026-86341 · GitLab EE (protected environment deployment approval rules)Medium
- Grafana: A user can block another user's login by registering their email address as a usernameCVE-2022-39229 · GrafanaMedium
- Pure Storage FlashBlade object store protocol: An authenticated object-store user degrades both data access andCVE-2023-31042 · Pure Storage FlashBlade object store protocolMedium
- OpenVINO Model Server: Input-validation flaw in OpenVINO Model Server reachable without authenticationCVE-2023-31203 · OpenVINO Model ServerMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.