CVE-2023-28372: FlashBlade Object Store Privileged Access
A flaw exists in FlashBlade Purity (OE) Version 4.1.0 whereby a user with privileges to extend an object’s retention period can affect the availability of the object lock.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-28372?
CVE-2023-28372 is a vulnerability in FlashBlade Purity (OE) Version 4.1.0 that allows a user with privileges to extend an object's retention period to affect the availability of the object lock.
How severe is CVE-2023-28372?
CVE-2023-28372 has a severity rating of medium.
Which software version is affected by CVE-2023-28372?
FlashBlade Purity (OE) Version 4.1.0 is affected by CVE-2023-28372.
How can CVE-2023-28372 be fixed?
To fix CVE-2023-28372, users should consider upgrading their FlashBlade Purity (OE) software to a version that is not affected by the vulnerability.
Where can I find more information about CVE-2023-28372?
More information about CVE-2023-28372 can be found in the Pure Storage Technical Services Field Bulletins, specifically the Security Bulletin for FlashBlade Object Store Privileged Access Vulnerability.