Database/Control plane, storage & DevOps

IBM Storage Scale Container Native Storage Access (network namespace exposure): Hosts outside the cluster can open
Impact
Hosts outside the cluster can open connections directly to CNSA containers, bypassing whatever ingress policy the operator thought was in force. Container-internal services that were only ever meant to be cluster-local become externally addressable.
Who can reach it
Network position outside the Kubernetes cluster with a route to the node network. No credentials required.
What to do
Upgrade Storage Scale CNSA to the fixed level from IBM's bulletin, then confirm with an external port scan that the driver containers are no longer answering. Add explicit NetworkPolicy denying ingress to the storage namespace as defence in depth.
References
Related entries
- Schneider Electric APC NetBotz 4 environmental appliances (355/450/455/550/570, V4.7.0 and prior): No rate limitingCVE-2022-43377 · Schneider Electric APC NetBotz 4 environmental appliances (355/450/455/550/570, V4.7.0 and prior)High
- Linux nfsd (NFS server): NFSD buffer overflow - a client can force the send buffer to overflow the page arrayCVE-2022-43945 · Linux nfsd (NFS server)High
- GlusterFS (dht translator, dht_setxattr_mds_cbk): A use-after-free in the distributed-hash translator crashes the brickCVE-2022-48340 · GlusterFS (dht translator, dht_setxattr_mds_cbk)High
- AMD SMM communications buffer - TOCTOU (AMD-SB-3003): A time-of-check-to-time-of-use race on the SMM communicationsCVE-2023-20578 · AMD SMM communications buffer - TOCTOU (AMD-SB-3003)High
- NetApp ONTAP 9 HTTP service: An unauthenticated attacker crashes the ONTAP HTTP service, taking down the management andCVE-2023-27314 · NetApp ONTAP 9 HTTP serviceHigh
- Veeam Backup & Replication: Encrypted credentials in the configuration database can be obtainedCVE-2023-27532 · Veeam Backup & ReplicationHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.