First published: Tue Dec 13 2022(Updated: )
IBM Spectrum Scale 5.1 could allow users with permissions to create pod, persistent volume and persistent volume claim to access files and directories outside of the volume, including on the host filesystem. IBM X-Force ID: 235740.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Spectrum Scale | <=5.1.4.0 | |
Linux Linux kernel | ||
<=CSI 2.6.0 or before (CNSA 5.1.4.0 or before) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2022-40607.
The severity level of CVE-2022-40607 is medium.
IBM Spectrum Scale version 5.1.4.0 is affected by CVE-2022-40607.
CVE-2022-40607 allows users with permissions to access files and directories outside of the volume, including on the host filesystem.
To fix CVE-2022-40607, upgrade to a version of IBM Spectrum Scale that is not affected by this vulnerability.