GPU VulnDB

Database/Control plane, storage & DevOps

Pure Storage FlashBlade object store protocol: An authenticated object-store user degrades both data access and

CVE-2023-31042Control plane, storage & DevOpscurated

Impact

An authenticated object-store user degrades both data access and replication for the whole array. One tenant's S3 client can therefore interrupt everyone else's reads and break the copy that was supposed to be the recovery point.

Who can reach it

Any authenticated client of the FlashBlade object store protocol - the same access a tenant needs to use their own bucket.

What to do

Upgrade Purity//FB to the fixed release named in Pure's bulletin. Monitor replication lag as a signal while unpatched, since the replication impact is the part that quietly breaks recovery.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.