Database/AI/ML frameworks & serving
Pure Storage FlashArray Purity API endpoint: A specific call to a FlashArray endpoint escalates the caller's privileges
Impact
A specific call to a FlashArray endpoint escalates the caller's privileges on the array, which puts every volume, snapshot and host mapping under attacker control.
Who can reach it
Network access to the FlashArray management endpoint. The CVSS vector records no privileges required, so treat any route to the management interface as sufficient.
What to do
Upgrade Purity//FA to the fixed release Pure names in its security bulletin. Confirm the array's management interface is not reachable from tenant or compute networks, and audit recently created accounts and host mappings.
References
Related entries
- TorchServe: `allowed_urls` bypassCVE-2024-35198 · TorchServeCritical
- Keras / TensorFlow: Arbitrary code injection in Keras < 2.13 via Lambda-layer model loadingCVE-2024-3660 · Keras / TensorFlowCritical
- Gradio: Code injection via `gradio/component_meta.py`CVE-2024-39236 · GradioCritical
- langchain-experimental: Arbitrary code execution in 0.1.17–0.3.0CVE-2024-46946 · langchain-experimentalCritical
- Gradio: SSRF from the file-upload/proxy pathCVE-2024-47167 · GradioCritical
- PyTorch (`torch.distributed` RemoteModule / RPC): Deserialization RCE across the distributed RPC channelCVE-2024-48063 · PyTorch (`torch.distributed` RemoteModule / RPC)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.