Database/Control plane, storage & DevOps
Pure Storage FlashBlade object store protocol: An authenticated object-store user degrades both data access and
Impact
An authenticated object-store user degrades both data access and replication for the whole array. One tenant's S3 client can therefore interrupt everyone else's reads and break the copy that was supposed to be the recovery point.
Who can reach it
Any authenticated client of the FlashBlade object store protocol - the same access a tenant needs to use their own bucket.
What to do
Upgrade Purity//FB to the fixed release named in Pure's bulletin. Monitor replication lag as a signal while unpatched, since the replication impact is the part that quietly breaks recovery.
References
Related entries
- OpenVINO Model Server: Input-validation flaw in OpenVINO Model Server reachable without authenticationCVE-2023-31203 · OpenVINO Model ServerMedium
- GitLab: crafted Git ref names make the web UI show different content than the downloaded archiveCVE-2025-12506 · GitLab CE/EE (Git reference name resolution)Medium
- Kibana: Open redirect leading to SSRF via a specially crafted URLCVE-2025-25012 · KibanaMedium
- Grafana: alert rules API returns rules from folders the user cannot readCVE-2026-13719 · Grafana (alert rules API list endpoint, folder authorization)Medium
- GitLab EE: developer-role user can influence the execution environment of Pipeline Execution Policy jobsCVE-2026-15387 · GitLab EE (Pipeline Execution Policy enforcement jobs, job dependency handling)Medium
- GitLab EE: Security Manager role can run arbitrary CI/CD jobs and read protected variablesCVE-2026-16794 · GitLab EE (compliance framework management authorization)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.