PT-2022-25417 · Ibm · Ibm Spectrum Scale
Published
2022-12-19
·
Updated
2022-12-23
·
CVE-2022-40607
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Spectrum Scale version 5.1
Description
The issue allows users with permissions to create pod, persistent volume, and persistent volume claim to access files and directories outside of the volume, including on the host filesystem.
Recommendations
For IBM Spectrum Scale version 5.1, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Spectrum Scale