Database/Control plane, storage & DevOps

HPE Cray Parallel Application Launch Service (PALS) authentication bypass: Authentication bypass in the service
Impact
Authentication bypass in the service that launches parallel jobs on Cray EX supercomputers. Bypassing PALS auth means launching arbitrary work on the cluster as another user - direct compromise of the HPC job-execution path.
Who can reach it
Unauthenticated network access to the PALS service on a Cray EX system.
What to do
Apply the HPE Cray fix per HPESBCR04653. This is a system-management-stack update on the Cray EX; coordinate with your Cray support contact because the update path is tied to the CSM release train, not a simple package bump.
References
Related entries
- Jenkins: CLI parser expands `@file` into argument contentsCVE-2024-23897 · JenkinsCritical
- LenelS2 NetBox access control and event monitoring system (<=5.6.1): Unauthenticated remote code executionCVE-2024-2421 · LenelS2 NetBox access control and event monitoring system (<=5.6.1)Critical
- JetBrains TeamCity: Alternative-path authentication bypassCVE-2024-27198 · JetBrains TeamCityCritical
- Veeam Backup Enterprise Manager: Unauthenticated users can log in as any user to the Enterprise Manager web interfaceCVE-2024-29849 · Veeam Backup Enterprise ManagerCritical
- CyberPower PowerPanel platform - hardcoded database, service and cloud credentials: Hardcoded credentials usedCVE-2024-32053 · CyberPower PowerPanel platform - hardcoded database, service and cloud credentialsCritical
- CyberPower PowerPanel Enterprise prior to v2.8.3 - PDNU REST APIs: Certain utility REST APIs have no authenticationCVE-2024-32735 · CyberPower PowerPanel Enterprise prior to v2.8.3 - PDNU REST APIsCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.