Database/Control plane, storage & DevOps
Fortra BoKS Manager: command injection in crlserver gives root on the BoKS Master via a crafted CRL URL
Impact
BoKS Manager is the privileged-access and keystroke-control layer enterprises put in front of their Unix and Linux server estates - it decides who may become root on which host. An administrator authorized to add CRL URLs can get shell command substitution processed by crlserver as root on the BoKS Master. The Master is the policy authority for every enrolled host, so root there means control over access decisions across the managed fleet, which on a GPU estate is every login and every privileged action on the compute nodes. CVSS scope is marked changed (S:C) for this reason. Two of the three entry points - BCC and the WSI REST/SOAP API - are network-accessible administration paths and need no local sudo or suexec rule; only non-root use of the cacrl CLI does.
Who can reach it
An authenticated user already authorized to add CRL URLs, through the BCC console, the WSI REST or SOAP API, or the cacrl CLI. High privilege required (PR:H), but reachable over the network via BCC/WSI.
What to do
Apply the fix from Fortra advisory FI-2026-015; the record here does not name a fixed version, so take it from the advisory. Patching the BoKS Master means updating and restarting the BoKS server processes on the Master - the enrolled hosts are not touched, but access decisions depend on the Master, so schedule it like any change to the authentication path. Interim mitigation is to audit and tighten who is authorized to add CRL URLs and who can reach BCC and the WSI API.
References
Related entries
- Airflow FAB provider: password change through the Admin PATCH endpoint does not evict existing sessionsCVE-2026-86462 · Apache Airflow FAB provider (Admin user-edit PATCH endpoint, session invalidation)Critical
- Apache Airflow: Core API logout does not revoke bearer tokens, so a stolen token outlives the sessionCVE-2026-86473 · Apache Airflow Core API (logout endpoint, bearer-token revocation)Critical
- AMD EPYC / Ryzen - Hardware Validated Boot enforcement: Hardware Validated Boot is not properly enforced, so anCVE-2018-8930 · AMD EPYC / Ryzen - Hardware Validated Boot enforcementCritical
- AMD EPYC Server - protected memory region access control: Insufficient access control over protected memory regions onCVE-2018-8933 · AMD EPYC Server - protected memory region access controlCritical
- PC-DDR4 / LPDDR4X DRAM - Target Row Refresh mitigation: Non-uniform Rowhammer patterns triggered bit flips on every oneCVE-2021-42114 · PC-DDR4 / LPDDR4X DRAM - Target Row Refresh mitigationCritical
- Digi RealPort protocol (Digi console/terminal servers): RealPort is the protocol Digi console servers use to exposeCVE-2023-4299 · Digi RealPort protocol (Digi console/terminal servers)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.