GPU VulnDB

Database/Control plane, storage & DevOps

Pure Storage Purity//FA and Purity//FB restricted shell (environment variables): A second route out of the restricted

CVE-2022-32553Control plane, storage & DevOpscurated

Impact

A second route out of the restricted array shell to a root shell, this one through general environment variable manipulation rather than the Python-specific path. Same outcome: an array operator becomes root on the appliance.

Who can reach it

Any valid shell login on an affected FlashArray or FlashBlade.

What to do

Apply the same Pure patch or Purity upgrade that fixes the sibling issue - they ship together in the 2022-04-04 security bundle. Verify after patching that the restricted shell actually rejects an environment override attempt.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.