Database/Control plane, storage & DevOps

IBM Spectrum Scale Data Access Services (DAS): An authenticated DAS user inserts code that manipulates cluster
Impact
An authenticated DAS user inserts code that manipulates cluster resources, because DAS runs with more permission than the caller should inherit. The user ends up changing shared cluster state rather than just their own data path.
Who can reach it
Any authenticated user of the Data Access Services layer in Spectrum Scale DAS 5.1.3.1 - typically the S3/object front end offered to tenants.
What to do
Upgrade DAS to the fixed level in IBM's bulletin and restart the service. Review which service account DAS runs as and tighten it so an escape yields less.
References
Related entries
- FlyteAdmin (external IdP access token / ID token expiration check): FlyteAdmin does not enforce expiry on access and IDCVE-2022-31145 · FlyteAdmin (external IdP access token / ID token expiration check)Medium
- HashiCorp Consul: Internal RPC endpoint does not check multiple SAN URIs in a CSRCVE-2022-40716 · HashiCorp ConsulMedium
- AMD IOMMU - not re-initialized during DRTM (AMD-SB-3003): The IOMMU is not re-initialized during a Dynamic Root ofCVE-2023-20591 · AMD IOMMU - not re-initialized during DRTM (AMD-SB-3003)Medium
- Netdata: Agent MACHINE GUID is readable and reusableCVE-2023-22497 · NetdataMedium
- Apache Guacamole: Miscalculated instruction lengths during the Guacamole handshakeCVE-2023-30575 · Apache GuacamoleMedium
- Elasticsearch: Crafted _search query stringCVE-2023-31419 · ElasticsearchMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.