GPU VulnDB

Database/Control plane, storage & DevOps

Pure Storage Purity//FA and Purity//FB restricted shell (Python environment variables): A logged-in user manipulates

CVE-2022-32552Control plane, storage & DevOpscurated

Impact

A logged-in user manipulates Python environment variables to break out of the restricted array shell into an unrestricted root shell. The restricted shell is the whole boundary between an array operator and the appliance operating system, and it does not hold.

Who can reach it

Any valid login to an affected FlashArray or FlashBlade shell - including a low-privilege operator account handed out for day-to-day array work.

What to do

Apply Pure's opt-in or manual patch, or upgrade Purity to an unaffected release. Treat every account that had shell access on an affected array as having had root, and rotate anything reachable from the appliance.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.