Database/Control plane, storage & DevOps

IBM Storage Scale session management: An authenticated user steals or fixates another user's active session and
CVSS 8.8CVE-2023-38002Control plane, storage & DevOpscurated
Impact
An authenticated user steals or fixates another user's active session and inherits their rights. If the victim is a storage administrator, the attacker owns the management plane for the whole cluster.
Who can reach it
Any authenticated user of Storage Scale 5.1.0.0 through 5.1.9.2 who can reach the session-bearing interface. No admin role needed as a starting point.
What to do
Upgrade to 5.1.9.3 or later. After upgrading, invalidate all existing sessions and force re-authentication - the fix does not retire sessions that were already fixated.
References
Related entries
- A10 Thunder ADC (FileMgmtExport): An authenticated attacker can walk outside the intended export directoryCVE-2023-42130 · A10 Thunder ADC (FileMgmtExport)High
- Linux NVMe-oF (nvmet-tcp): Use-after-free/double-free in nvmet_tcp_free_cryptoCVE-2023-5178 · Linux NVMe-oF (nvmet-tcp)High
- PostgreSQL: PL/Perl lets an unprivileged DB user change process env vars (e.g. PATH)CVE-2024-10979 · PostgreSQLHigh
- Cisco Nexus Dashboard Fabric Controller (path traversal to RCE via SCP): A low-privileged authenticated attackerCVE-2024-20449 · Cisco Nexus Dashboard Fabric Controller (path traversal to RCE via SCP)High
- Cisco Nexus Dashboard Fabric Controller (SQL injection): A read-only NDFC user executes arbitrary SQL on the controllerCVE-2024-20536 · Cisco Nexus Dashboard Fabric Controller (SQL injection)High
- Jenkins: No origin validation on the CLI WebSocket endpointCVE-2024-23898 · JenkinsHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.