Database/Control plane, storage & DevOps
Pure Storage Purity//FA and Purity//FB restricted shell (environment variables): A second route out of the restricted
CVE-2022-32553Control plane, storage & DevOpscurated
Impact
A second route out of the restricted array shell to a root shell, this one through general environment variable manipulation rather than the Python-specific path. Same outcome: an array operator becomes root on the appliance.
Who can reach it
Any valid shell login on an affected FlashArray or FlashBlade.
What to do
Apply the same Pure patch or Purity upgrade that fixes the sibling issue - they ship together in the 2022-04-04 security bundle. Verify after patching that the restricted shell actually rejects an environment override attempt.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.