PT-2024-14292 · Lustre · Lustre

Published

2024-03-07

·

Updated

2024-08-27

·

CVE-2023-51786

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Lustre versions 2.13.x through 2.15.x before 2.15.4 Lustre version 2.15.4 is not affected, so the range can be simplified to: Lustre versions 2.13.x through 2.15.3
Description The issue allows attackers to escalate privileges and obtain sensitive information via Incorrect Access Control.
Recommendations For Lustre versions 2.13.x through 2.15.3, update to version 2.15.4 or later to resolve the issue.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2023-51786

Affected Products

Lustre