Database/Control plane, storage & DevOps
Pure Storage FlashArray Purity (array admin command execution): A user holding the array admin role executes arbitrary
CVSS 9.1CVE-2024-0004Control plane, storage & DevOpscurated
Impact
A user holding the array admin role executes arbitrary commands remotely and escalates beyond the intended management boundary onto the array's underlying OS.
Who can reach it
Authenticated array admin.
What to do
Apply the Purity update from Pure's security page.
References
Related entries
- Pure Storage FlashArray / FlashBlade Purity (SNMP configuration command injection): A crafted SNMP configuration yieldsCVE-2024-0005 · Pure Storage FlashArray / FlashBlade Purity (SNMP configuration command injection)Critical
- Ivanti Connect Secure: Command injection in web componentsCVE-2024-21887 · Ivanti Connect SecureCritical
- Zabbix: Unsanitized clientip in the audit logCVE-2024-22120 · ZabbixCritical
- Kibana: Prototype pollution via ML/Alerting connectors + write access to internal ML indicesCVE-2024-37287 · KibanaCritical
- Linux NFS server (nfsd, NFSv4 COMPOUND tag decode): An NFSv4 COMPOUND tag length near U32_MAX overflows the length+4CVE-2024-53146 · Linux NFS server (nfsd, NFSv4 COMPOUND tag decode)Critical
- GitHub Enterprise Server: Improper signature verificationCVE-2024-9487 · GitHub Enterprise ServerCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.