CVE-2023-36627: FlashBlade Snapshot Scheduler
A flaw exists in FlashBlade Purity whereby a user with access to an administrative account on a FlashBlade that is configured with timezone-dependent snapshot schedules can configure a timezone to prevent the schedule from functioning properly.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-36627?
CVE-2023-36627 is a vulnerability that exists in FlashBlade Purity and allows a user with administrative account access to configure a timezone to prevent snapshot schedules from functioning properly.
Who is affected by CVE-2023-36627?
Users of FlashBlade with Purity versions 3.3.7, 4.0.0 to 4.0.5, and 4.1.0 to 4.1.2 are affected by CVE-2023-36627.
What is the severity of CVE-2023-36627?
CVE-2023-36627 has a severity keyword of 'high' and a severity value of 2.7.
How can I fix CVE-2023-36627?
To fix CVE-2023-36627, Pure Storage recommends updating to a fixed version of Purity that addresses the vulnerability.
Where can I find more information about CVE-2023-36627?
You can find more information about CVE-2023-36627 in the security bulletin provided by Pure Storage: [Security Bulletin for FlashBlade Snapshot Scheduler CVE-2023-36627](https://support.purestorage.com/Pure_Storage_Technical_Services/Field_Bulletins/Security_Bulletins/Security_Bulletin_for_FlashBlade_Snapshot_Scheduler_CVE-2023-36627)