Database/Control plane, storage & DevOps

Lustre (incorrect access control, 2.13.x-2.15.x before 2.15.4): Incorrect access control in Lustre lets an attacker
Impact
Incorrect access control in Lustre lets an attacker escalate privileges and obtain sensitive information. This is the modern-release equivalent of the 2019 family and it lands on the versions actually deployed in current AI-training clusters — 2.15.x is the long-term-support line most sites run today. On a shared training filesystem, 'obtain sensitive information' means another tenant's datasets, checkpoints and model weights.
Who can reach it
An attacker with Lustre client access on versions 2.13.x, 2.14.x, or 2.15.x before 2.15.4.
What to do
Upgrade to Lustre 2.15.4 or later — client and server packages, with a coordinated restart of the storage cluster. Enable Lustre nodemap with admin/trusted set to off for tenant clients and squash root, so a compromised client cannot act as root against the filesystem; that is a config change you can make ahead of the upgrade and it is the durable control.
References
Related entries
- Pure Storage FlashArray Purity (remote administrative account creation): An attacker uses a remote administrativeCVE-2024-0003 · Pure Storage FlashArray Purity (remote administrative account creation)Critical
- Pure Storage FlashArray Purity (array admin command execution): A user holding the array admin role executes arbitraryCVE-2024-0004 · Pure Storage FlashArray Purity (array admin command execution)Critical
- Pure Storage FlashArray / FlashBlade Purity (SNMP configuration command injection): A crafted SNMP configuration yieldsCVE-2024-0005 · Pure Storage FlashArray / FlashBlade Purity (SNMP configuration command injection)Critical
- Ivanti Connect Secure: Command injection in web componentsCVE-2024-21887 · Ivanti Connect SecureCritical
- Zabbix: Unsanitized clientip in the audit logCVE-2024-22120 · ZabbixCritical
- Kibana: Prototype pollution via ML/Alerting connectors + write access to internal ML indicesCVE-2024-37287 · KibanaCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.