GPU VulnDB

Database/Control plane, storage & DevOps

IBM Spectrum Scale Data Access Services (DAS): An authenticated DAS user inserts code that manipulates cluster

CVE-2022-22411Control plane, storage & DevOpscurated

Impact

An authenticated DAS user inserts code that manipulates cluster resources, because DAS runs with more permission than the caller should inherit. The user ends up changing shared cluster state rather than just their own data path.

Who can reach it

Any authenticated user of the Data Access Services layer in Spectrum Scale DAS 5.1.3.1 - typically the S3/object front end offered to tenants.

What to do

Upgrade DAS to the fixed level in IBM's bulletin and restart the service. Review which service account DAS runs as and tighten it so an escape yields less.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.