Database/Control plane, storage & DevOps

HPE OneView (command injection with local privilege escalation): A low-privileged local user on the OneView appliance
CVE-2023-50274Control plane, storage & DevOpscurated
Impact
A low-privileged local user on the OneView appliance injects commands and escalates - full control of the fleet management appliance.
Who can reach it
Local low-privilege access to the OneView appliance.
What to do
Apply the OneView update per HPESBGN04586. Appliance update with restart.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.